← Microsec Ltd. cases
Bugzilla #1886257 Certificate Misissuance

Microsec: Misissuance of an EV TLS certificate without CPSuri

RESOLVED FIXED Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsec reported that it misissued an EV TLS certificate because the certificate did not contain the CPSuri link, which Microsec stated is mandatory for EV TLS certificates. Microsec said it did not react in time to the initial email reporting a potentially misissued certificate, and it opened this bug to focus on the certificate misissuance (with other related issues handled in separate bugs). Microsec investigated and determined the issue started with a certificate profile change released on 2023-08-29, when it removed policyQualifiers information based on its interpretation of CABF EVG requirements. Microsec modified its EV TLS certificate profiles, issued a new EV TLS certificate containing CPSuri, and revoked the misissued certificate. Microsec later reported that a total of 45 EV TLS certificates were misissued, and that revocation of the misissued certificates was completed, with two PSD2 certificates revoked later in a related bug. In the thread, Microsec stated there were no open issues remaining regarding this incident report, and Mozilla indicated it would close the bug on or about 28-Aug-2024.

Model: gpt-5.4-nano Generated: 2026-06-13 21:14 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.90 9 comments
Chronology
  1. Microsec released a new version of its certificate profiles that led to EV TLS certificates being issued without required CPSuri information.
  2. Microsec received an email reporting a potentially misissued certificate.
  3. Microsec received a second email reporting a potentially misissued certificate and began investigation.
  4. Microsec opened this Bugzilla incident report focusing on certificate misissuance.
  5. Microsec issued a corrected EV TLS certificate containing CPSuri and revoked the misissued certificate.
  6. Microsec reported revoking 44 of 46 misissued certificates.
  7. Microsec reported revoking the remaining 2 PSD2 misissued certificates and finishing revocation of all misissued certificates.
  8. Mozilla asked whether anything remained to be done; Microsec said no open issues remained and Mozilla planned to close the bug on or about 28-Aug-2024.
Thread Activity
  1. Microsec representative — Opened the incident report, stating Microsec misissued an EV certificate missing CPSuri and describing the investigation and corrective actions, including issuing a new CPSuri-containing certificate and revoking the misissued one.
  2. Microsec representative — Provided an incident status update, including that 44 of 45 misissued certificates were issued/replaced and that revocation progress and customer coordination were underway, with PSD2-related items handled in Bug #2.
  3. Microsec representative — Reported that 44 of 46 misissued certificates were revoked and that 2 PSD2 certificates would be revoked later, referencing Bug #2.
  4. Microsec representative — Reported that the revocation of all misissued certificates was finished after the remaining 2 PSD2 certificates were revoked.
  5. Microsec representative — Shared additional details for checking revocation status, including serials and revocation information for affected certificates.
  6. Microsec representative — Described process improvements to prevent similar errors, explaining how certificate profile change management failed to account for different EV certificate requirements.
  7. Mozilla representative — Asked whether anything remained to be done regarding the incident report.
  8. Microsec representative — Stated there were no open issues regarding this incident report.
  9. Mozilla representative — Indicated the bug would be closed on or about Wed. 28-Aug-2024.
Participants
Microsec representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1728384 RESOLVED Certificate Misissuance Incident Opened 2021-08-31 · Closed 2023-02-22 · 97% similar
Microsec: Misissuance of one OV certificate with Key Usage KeyEncipherment
#1676352 RESOLVED Certificate Misissuance Incident Opened 2020-11-10 · Closed 2023-02-22 · 95% similar
Microsec: Certificate validity period greater than 398 days
#1512270 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-12-05 · Closed 2023-02-22 · 81% similar
Microsec: Validity period greater than 825 days
#1649947 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 78% similar
Microsec: Incorrect OCSP Delegated Responder Certificate
#1850807 RESOLVED Certificate Misissuance Opened 2023-08-30 · Closed 2023-09-29 · 70% similar
IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement
#1766525 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-04-26 · Closed 2023-02-22 · 70% similar
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability
#1743935 RESOLVED Certificate Misissuance Incident Opened 2021-12-02 · Closed 2023-02-22 · 70% similar
Amazon Trust Services: Misissuance of Subordinate Per CPS
#1650018 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 69% similar
GlobalSign: Cross Certificate with non-conforming CABF Policy OIDs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action