← SwissSign AG cases
Bugzilla #1894054 Certificate Misissuance

SwissSign: MPKI step-up process sets wrong JoI Locality

RESOLVED FIXED SwissSign AG
AI Summary

SwissSign AG reported a mis-issuance of 18 Extended Validation (EV) certificates due to incorrect jurisdiction of incorporation (JoI) locality fields during a walkthrough of their MPKI step-up process. This issue was identified during an audit review session, and all affected certificates have since been revoked. The mis-issuance was attributed to a failure in the user interface and backend checks that should have prevented the entry of locality information for organizations registered at the state level. SwissSign has implemented corrective actions and enhanced their procedures to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 20:49 UTC Confidence: 0.95
Chronology
  1. Guidelines for the Issuance and Management of Extended Validation Certificates Version 1.8.1 released
  2. Walkthrough of the MPKI step-up process and issuance of EV certificates
  3. Discovery of mis-issuance during audit review session
  4. Reporting of additional mis-issued certificates
  5. Correction of error in the step-up process completed
Participants
Sandy Balzer Amir Aamidi Mathew Hodson Roman Fischer B Wilson
Similar Local Cases
#1851164 RESOLVED Certificate Misissuance Opened 2023-09-01 · Closed 2023-09-22 · 69% similar
SwissSign: S/MIME wrong key Usage
#1874196 RESOLVED Certificate Misissuance Opened 2024-01-11 · Closed 2024-03-27 · 66% similar
SwissSign: difference in upper and lower case between CN field and SAN
#1866091 RESOLVED Certificate Misissuance Opened 2023-11-22 · Closed 2023-12-11 · 63% similar
SwissSign: EV JurisdictionStateOrProvinceName - one certificate not selected for revocation
#1914023 RESOLVED Certificate Misissuance Opened 2024-08-20 · Closed 2025-04-03 · 61% similar
SwissSign: S/MIME LCP not-permitted key usage
#1914020 RESOLVED Certificate Misissuance Opened 2024-08-20 · Closed 2024-09-13 · 60% similar
SwissSign: S/MIME NCP non ASCII symbols in email and SAN field wrong coding
#1876771 RESOLVED Certificate Misissuance Opened 2024-01-26 · Closed 2024-02-08 · 60% similar
SwissSign: modified fields were not saved into certificates and resulted in miss-issuance
#1916489 RESOLVED Certificate Misissuance Opened 2024-09-03 · Closed 2025-03-18 · 60% similar
SwissSign: LDAP URL still in CRL distribution point (CDP)
#1848854 RESOLVED Certificate Misissuance Opened 2023-08-15 · Closed 2024-03-27 · 59% similar
SwissSign: S/MIME LCP: CN with values other than email address

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action