← e-commerce monitoring GmbH cases
Bugzilla #1883711
Certificate Problem Report
e-commerce monitoring gmbh: precertificate validity does not match leaf certificate
RESOLVED
WONTFIX
e-commerce monitoring GmbH
AI Summary
The case involves a misissuance by e-commerce monitoring gmbh where a Pre-Certificate and its corresponding Leaf Certificate were issued with differing validity periods, violating RFC 6962. The issue was reported on March 4, 2024, leading to an investigation and subsequent revocation of both certificates. E-commerce monitoring gmbh acknowledged the problem and is implementing corrective actions, including a bug fix and retraining of staff. However, they have faced criticism for their incident response procedures and the handling of similar issues in the past.
Chronology
- Issuance of a Pre-Certificate
- Issuance of Leaf Certificate
- Receipt of a Certificate Problem Report
- Filing of this bug
Participants
Daniel Zens
aaron@letsencrypt.org
agwa-bugs@mm.beanwood.com
dzacharo@harica.gr
External References
Similar Local Cases
e-commerce monitoring GmbH: SCT in precertificate
e-commerce monitoring GmbH: CN domain not in SAN
e-commerce monitoring GmbH: CRLs with mismatched issuer
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
Telia: Invalid email contact address was used for few domains
SSL.com: CAA Empty set handling results in Wildcard issuance