← certSIGN cases
Bugzilla #1886624 Certificate Problem Report

certSIGN: Certificates with incorrect Subject attribute order

RESOLVED FIXED certSIGN
AI Summary

certSIGN issued 625 TLS certificates with an incorrect order of Subject attributes, violating BR section 7.1.4.2. Upon discovering the issue on March 18, 2024, certSIGN halted all TLS certificate issuance and began revoking affected certificates. The root cause was identified as a misconfiguration in their linter software, which failed to catch the error. Corrective actions included fixing the linter configuration and reviewing the software update testing process. All affected certificates have since been revoked and reissued.

Model: gpt-4o-mini Generated: 2026-06-13 21:28 UTC Confidence: 1.00
Chronology
  1. certSIGN stopped issuance of TLS certificates after discovering the issue.
  2. certSIGN completed the search for affected certificates.
  3. certSIGN informed auditors and restarted issuance of TLS certificates.
  4. certSIGN revoked and reissued all affected certificates.
  5. certSIGN considered the bug resolved.
Participants
Gabriel PETCU
External References
Similar Local Cases
#1924497 RESOLVED Certificate Problem Report Opened 2024-10-14 · Closed 2025-01-31 · 62% similar
certSIGN: Missing certificate from the list of bad order subject attributtes
#1763173 RESOLVED Certificate Problem Report Opened 2022-04-05 · Closed 2023-02-22 · 59% similar
certSIGN: Incorrect data in stateOrProvinceName
#2025318 RESOLVED Certificate Problem Report Opened 2026-03-23 · Closed 2026-05-26 · 58% similar
certSIGN: delay in updating a Bugzilla ticket
#2016672 RESOLVED Certificate Problem Report Opened 2026-02-13 · Closed 2026-03-30 · 58% similar
certSIGN: certificates with delayed SCT signature
#1965807 RESOLVED Certificate Problem Report Opened 2025-05-12 · Closed 2025-06-04 · 57% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #4 – Expired cert with bad order of attributes
#1886626 RESOLVED Certificate Problem Report Opened 2024-03-20 · Closed 2024-06-01 · 57% similar
certSIGN: Delayed response to CPR
#1886627 RESOLVED Certificate Problem Report Opened 2024-03-20 · Closed 2024-06-01 · 56% similar
certSIGN: Delayed revocation
#1398243 RESOLVED Certificate Problem Report Opened 2017-09-08 · Closed 2023-02-22 · 50% similar
certSIGN: Non-BR-Compliant OCSP Responders

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action