← NAVER Cloud Trust Services cases
Bugzilla #1908128 Self Reported Incident Certificate Misissuance

NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA

RESOLVED FIXED NAVER Cloud Trust Services
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

NAVER Cloud Trust Services reported that, on 2024-07-16, its NAVER Cloud Trust Services G1 ECC CA1 intermediate CA issued certificates for test websites with an incorrect OCSP URI in the Authority Information Access (AIA) extension. The issue was detected via sslmate OCSP WATCH, which reported an error parsing the OCSP response due to an ECDSA verification failure. NAVER Cloud Trust Services stated that it revoked the affected certificate within 30 minutes of becoming aware of the problem and suspended certificate issuance while investigating. In its incident report, the CA attributed the root cause to human error when creating a certificate profile: the OCSP URI intended for CA certificates was entered instead of the OCSP URI intended for end-entity certificates. The CA also described action items to prevent recurrence, including changing the certificate issuance system so AIA extension caIssuer and OCSP URI values are selected from constants rather than manually entered, and adding verification logic to cross-check that the OCSP URI and caIssuer URI match the intended CA purpose. The bug was marked RESOLVED with resolution FIXED, and the CA later stated that analysis and actions were completed with no new information since the prior comment.

Model: gpt-5.4-nano Generated: 2026-06-13 20:55 UTC Revised: 2026-06-16 18:39 UTC Confidence: 0.88 8 comments
Chronology
  1. NAVER Cloud Trust Services issued test-site certificates with an incorrect OCSP URI in the AIA extension, then revoked the affected certificate within about 30 minutes and suspended issuance.
Thread Activity
  1. Navercorp representative — Posted a preliminary incident report stating the incorrect OCSP URI was detected by sslmate OCSP WATCH and that the affected certificate was revoked within 30 minutes; also said issuance was being suspended and a full report would follow by 2024-07-23.
  2. Navercorp representative — Provided an incident report describing the mis-issuance, impact, timeline, root cause (human error entering the wrong OCSP URI in the AIA field during certificate profile creation), and action items to prevent manual misconfiguration and add verification logic.
  3. Apple representative — Requested additional detail about the necessity of manual certificate issuance/profile creation, the controls around profile configuration and issuance, and how these systems relate to another incident (1908130) and to NAVER Global Root CA operations.
  4. Navercorp representative — Responded with details of the certificate profile creation process, including development-environment testing and production profile creation steps, and discussed prior technical controls such as pre-lint validation.
  5. Navercorp representative — Updated the action items status, stating implementation was in progress for constant selections for AIA caIssuer/OCSP URI and for adding cross-verification logic.
  6. Navercorp representative — Updated the action items status to completed for both the constant-selection change and the added verification logic.
  7. Navercorp representative — Stated that analysis and actions were completed and that there was no new information since the prior comment.
  8. Mozilla representative — Indicated they would look at closing the bug next Wednesday (28-Aug-2024).
Participants
Navercorp representative Apple representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1908130 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 100% similar
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
#1866448 RESOLVED Certificate Misissuance Incident Opened 2023-11-24 · Closed 2024-02-14 · 97% similar
NAVER Cloud Trust Services: DV Certificate issued with improperly validated
#1843268 RESOLVED Self Reported Incident Opened 2023-07-13 · Closed 2024-05-09 · 91% similar
NAVER Cloud Trust Services: OV certificate issued with OU field
#1845269 RESOLVED Certificate Misissuance Incident Opened 2023-07-25 · Closed 2023-09-29 · 91% similar
NAVER Cloud Trust Services: commonName not in SAN
#1772411 RESOLVED Self Reported Incident Opened 2022-06-02 · Closed 2024-05-09 · 89% similar
NAVER Cloud Trust Services: Failure to Respond to May 2022 Survey
#1894560 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-05-01 · Closed 2024-07-03 · 85% similar
DigiCert: Incorrect case in Business Category
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 80% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1766255 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-04-25 · Closed 2023-02-22 · 80% similar
SwissSign: Mis-Issuance of S/MIME certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action