← Microsec Ltd. cases
Bugzilla #1889699
Certificate Misissuance
Incident
Revocation Issue
Microsec: Disallowed subject attribute field in DV certificate
RESOLVED
FIXED
Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Microsec Ltd. reported a compliance issue regarding the issuance of DV certificates that incorrectly included the SerialNumber extension, which is not permitted. The issue was identified after receiving notifications from both internal and external sources. Microsec promptly initiated an investigation, confirmed the misissuance of 23 certificates, and revoked them. They updated their certificate profiles to remove the disallowed extension and revised their policies to prevent future occurrences. The incident was resolved with no ongoing issues reported.
Chronology
- Microsec received reports of misissued DV certificates containing the SerialNumber extension.
- Microsec revoked the misissued certificates and updated their certificate profiles.
Thread Activity
- Microsec representative — Microsec began investigating the issue after receiving reports of misissued DV certificates.
- Community commenter — Requested clarification on the impact and timeline of the misissued certificates.
- Microsec representative — Provided a detailed status report including the number of misissued certificates.
- Mozilla representative — Inquired about the readiness to close the incident report.
Participants
Microsec representative
Community commenter
Google representative
Mozilla representative
External References
Similar Local Cases
MICROSEC: Incident report - No OCSP status response for 2 Precertificates
Microsec: CT Logging mistakes
Microsec: Non-BR-Compliant Certificate Issuance
Microsec: "DV valid" test website certificate issued under incorrect root
Microsec: Certificate validity period greater than 398 days
SwissSign: Certificate Profile error for S/MIME MV
SSL.com: CAA Empty set handling results in Wildcard issuance
Sectigo: Incorrect OCSP responses