← Disig, a.s. cases
Bugzilla #1889672 Certificate Misissuance

Disig: Certificates with incorrect Subject attribute order

RESOLVED FIXED Disig, a.s.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Disig, a Certificate Authority, discovered that it had issued TLS certificates with an incorrect subject attribute order, violating TLS BR Section 7.1.4.2. This issue was identified during an investigation related to a previous bug. Disig promptly notified affected customers and ceased the issuance of TLS certificates until the root cause was determined. By April 9, 2024, all affected certificates had been revoked. Disig implemented a control for subject attribute order to prevent future occurrences and has committed to improving communication with its DevOps and DB teams regarding compliance requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:22 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.85 16 comments
Chronology
  1. Disig identified certificates with incorrect subject attribute order during an internal investigation.
  2. All affected certificates were revoked.
  3. Disig implemented a control for subject attribute order in its certificate issuance process.
Thread Activity
  1. Disig, a.s. — Preliminary report filed after discovering nonconforming subject attribute order in certificates.
  2. Disig, a.s. — Final incident report submitted detailing the revocation of affected certificates.
  3. Disig, a.s. — Control for subject attribute order implemented successfully.
Participants
Disig, a.s. Sectigo HARICA Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1888104 RESOLVED Certificate Misissuance Opened 2024-03-27 · Closed 2024-07-11 · 99% similar
Disig: TLS certificate with basicConstraints not marked as critical
#2007132 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-12-19 · Closed 2026-02-11 · 91% similar
Disig: Certificates with invalid embedded SCT signature
#1907667 RESOLVED Certificate Misissuance Opened 2024-07-12 · Closed 2024-08-17 · 89% similar
Disig: Two certificates with same serial number
#1895006 RESOLVED Certificate Misissuance Opened 2024-05-03 · Closed 2024-08-23 · 84% similar
IdenTrust: unintended creation of a Root CA certificate
#1390991 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 84% similar
Disig: Non-BR-Compliant Certificate Issuance
#1865080 RESOLVED Certificate Misissuance Opened 2023-11-16 · Closed 2024-01-04 · 80% similar
Asseco DS / Certum: TLS EV certificates with incorrect Subject attribute order
#1829746 RESOLVED Certificate Misissuance Opened 2023-04-24 · Closed 2023-06-02 · 79% similar
Sectigo: Certificate issuance delayed for more than 398 days after DCV was completed
#1927384 RESOLVED Certificate Misissuance Opened 2024-10-28 · Closed 2025-01-29 · 78% similar
iTrusChina: Issuance of certificates using keys previously reported as compromised

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action