← Microsec Ltd. cases
Bugzilla #1889699 Certificate Misissuance Incident Revocation Issue

Microsec: Disallowed subject attribute field in DV certificate

RESOLVED FIXED Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsec Ltd. reported a compliance issue regarding the issuance of DV certificates that incorrectly included the SerialNumber extension, which is not permitted. The issue was identified after receiving notifications from both internal and external sources. Microsec promptly initiated an investigation, confirmed the misissuance of 23 certificates, and revoked them. They updated their certificate profiles to remove the disallowed extension and revised their policies to prevent future occurrences. The incident was resolved with no ongoing issues reported.

Model: gpt-4o-mini Generated: 2026-06-13 21:15 UTC Revised: 2026-06-16 19:17 UTC Confidence: 0.85 13 comments
Chronology
  1. Microsec received reports of misissued DV certificates containing the SerialNumber extension.
  2. Microsec revoked the misissued certificates and updated their certificate profiles.
Thread Activity
  1. Microsec representative — Microsec began investigating the issue after receiving reports of misissued DV certificates.
  2. Community commenter — Requested clarification on the impact and timeline of the misissued certificates.
  3. Microsec representative — Provided a detailed status report including the number of misissued certificates.
  4. Mozilla representative — Inquired about the readiness to close the incident report.
Participants
Microsec representative Community commenter Google representative Mozilla representative
External References
Similar Local Cases
#1844514 RESOLVED Revocation Issue Incident Opened 2023-07-20 · Closed 2024-03-13 · 88% similar
MICROSEC: Incident report - No OCSP status response for 2 Precertificates
#2005939 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-12-14 · Closed 2026-03-13 · 82% similar
Microsec: CT Logging mistakes
#1391055 RESOLVED Ca Certificate Compliance Incident Opened 2017-08-16 · Closed 2023-02-22 · 81% similar
Microsec: Non-BR-Compliant Certificate Issuance
#2013576 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-01-30 · Closed 2026-02-27 · 78% similar
Microsec: "DV valid" test website certificate issued under incorrect root
#1676352 RESOLVED Certificate Misissuance Incident Opened 2020-11-10 · Closed 2023-02-22 · 75% similar
Microsec: Certificate validity period greater than 398 days
#2033000 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-04-17 · Closed 2026-07-09 · 74% similar
SwissSign: Certificate Profile error for S/MIME MV
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 74% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 73% similar
Sectigo: Incorrect OCSP responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action