← certSIGN cases
Bugzilla #1886624 Self Reported Incident

certSIGN: Certificates with incorrect Subject attribute order

RESOLVED FIXED certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

certSIGN reported that it had issued 625 TLS certificates since September 15, 2023 with an incorrect relative order of Subject attributes, as defined in BR section 7.1.4.2. The issue was triggered by a Certificate Problem Report received on March 18, 2024 indicating a non-conformity in Subject Attribute Encoding order. After acknowledging the report, certSIGN stopped issuance of all TLS certificates, corrected the Subject attribute order, and restarted issuance. certSIGN stated that it would revoke all affected certificates and later reported that it revoked and reissued all affected certificates. certSIGN also informed its WebTrust auditors about the incident and deployed a new update in production. In response to Mozilla’s question about preventing recurrence, certSIGN described improvements to its linter update and testing processes, including periodic checks and additional internal auditor review. The bug is marked RESOLVED with resolution FIXED, and a later comment notes that Bug 1965807 was marked as a duplicate of this bug.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 18:22 UTC Confidence: 0.86 9 comments
Chronology
  1. certSIGN stopped TLS certificate issuance after identifying an incorrect Subject attribute order and began correcting the issue.
  2. certSIGN deployed an update to production and restarted TLS certificate issuance.
  3. certSIGN revoked and reissued all affected certificates.
  4. certSIGN reported completion of reviewed testing steps and closure of action items.
  5. Mozilla indicated intent to close the bug unless further comments or questions were received.
  6. CCADB incident reporting marked Bug 1965807 as a duplicate of this bug.
Thread Activity
  1. certSIGN — Created an incident report stating certSIGN issued 625 TLS certificates with incorrect Subject attribute order, stopped issuance on March 18, corrected the order, restarted issuance, and planned to revoke affected certificates.
  2. certSIGN — Reported that certSIGN revoked and reissued all affected certificates.
  3. certSIGN — Stated the software update testing process was reviewed and that all action items were closed.
  4. certSIGN — Reiterated that the testing process review was completed and that all action items are closed.
  5. Mozilla representative — Asked what actions would ensure certSIGN linter(s) stay up to date with future certificate profile requirements.
  6. certSIGN — Described continuous monitoring of CA/B Forum ballots/guideline versions, added monthly periodic checks, and added quarterly internal auditor review of linters.
  7. Mozilla representative — Said Mozilla intended to close the bug next Wednesday (2024-06-05) unless additional comments or questions were received.
  8. CCADB representative — Noted that Bug 1965807 was marked as a duplicate of this bug.
Participants
certSIGN Mozilla representative CCADB representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#2025318 RESOLVED Self Reported Incident Opened 2026-03-23 · Closed 2026-05-26 · 97% similar
certSIGN: delay in updating a Bugzilla ticket
#1390979 RESOLVED Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 78% similar
certSIGN: Non-BR-Compliant Certificate Issuance
#1904041 RESOLVED Ca Documents Self Reported Incident Opened 2024-06-21 · Closed 2025-07-01 · 77% similar
NETLOCK: Intermediate CA Certificate not disclosed to CCADB
#2008803 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-12 · 77% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#1950574 RESOLVED Self Reported Incident Opened 2025-02-26 · Closed 2025-09-15 · 76% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#2008788 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-11 · 76% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#1955365 RESOLVED Self Reported Incident Opened 2025-03-20 · Closed 2025-05-19 · 76% similar
Apple: Public Key Reuse
#1940957 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-01-10 · Closed 2025-06-20 · 75% similar
Telia: TLS OV certificate with subject countryName and localityName mismatch

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action