← Disig, a.s. cases
Bugzilla #1889672
Certificate Problem Report
Disig: Certificates with incorrect Subject attribute order
RESOLVED
FIXED
Disig, a.s.
AI Summary
Disig, a.s. issued TLS certificates with an incorrect subject attribute order, violating TLS BR Section 7.1.4.2. The issue was identified during an investigation of a previous bug, leading to the revocation of 8 affected certificates. Disig halted the issuance of TLS certificates until the root cause was determined. The final affected certificate was revoked on April 12, 2024, and measures have been implemented to prevent future occurrences.
Chronology
- Preliminary report filed after discovering incorrect subject attribute order.
- Last affected certificate revoked.
- Control of Subject RDN order implemented.
Participants
Jozef Nigut
Martijn Katerbarg
External References
Similar Local Cases
Disig: TLS certificate with basicConstraints not marked as critical
Disig: Certificates with invalid embedded SCT signature
Disig: Two certificates with same serial number
Disig: Delayed Full Incident Report
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
Hongkong Post: TLS certificates with Certificate Policies extension that does not assert http scheme
Sectigo: S/MIME certificates with (null) string value in subject attributes
Disig: Missing CA Disig R2I2 Certification Service Full CRL URLs in CCADB