← SwissSign AG cases
Bugzilla #1914020 Certificate Misissuance

SwissSign: S/MIME NCP non ASCII symbols in email and SAN field wrong coding

RESOLVED FIXED SwissSign AG
AI Summary

SwissSign AG identified a misissuance of 98 S/MIME NCP certificates due to incorrect encoding of non-ASCII characters in the Subject Alternative Name (SAN) field. This issue was discovered during an annual audit, which revealed that the SAN field did not conform to the required standards. The affected certificates were revoked before the deadline, and measures have been implemented to prevent future occurrences, including the introduction of a linter to catch such errors. The incident highlights the importance of compliance with RFC standards in certificate issuance.

Model: gpt-4o-mini Generated: 2026-06-13 20:49 UTC Confidence: 0.95
Chronology
  1. S/MIME BR chapter 7.1.2.4 released, requiring compliance with RFC 5280.
  2. First mis-issuance of affected certificates.
  3. Last mis-issuance of affected certificates.
  4. Activation of S/MIME linter to prevent further mis-issuance.
  5. Revocation of all affected certificates completed.
  6. Completion of test-coverage for non-ASCII characters.
Participants
Sandy Balzer Stephan Verbücheln B. Wilson
External References
Similar Local Cases
#1914023 RESOLVED Certificate Misissuance Opened 2024-08-20 · Closed 2025-04-03 · 61% similar
SwissSign: S/MIME LCP not-permitted key usage
#1734131 RESOLVED Certificate Misissuance Opened 2021-10-05 · Closed 2023-02-22 · 60% similar
SwissSign: wrong address in EV certificate
#1894054 RESOLVED Certificate Misissuance Opened 2024-04-29 · Closed 2024-07-03 · 60% similar
SwissSign: MPKI step-up process sets wrong JoI Locality
#1916489 RESOLVED Certificate Misissuance Opened 2024-09-03 · Closed 2025-03-18 · 60% similar
SwissSign: LDAP URL still in CRL distribution point (CDP)
#1874196 RESOLVED Certificate Misissuance Opened 2024-01-11 · Closed 2024-03-27 · 59% similar
SwissSign: difference in upper and lower case between CN field and SAN
#1849364 RESOLVED Certificate Misissuance Opened 2023-08-18 · Closed 2023-09-22 · 58% similar
SwissSign: Missed revocation and opening Bugzilla
#1876771 RESOLVED Certificate Misissuance Opened 2024-01-26 · Closed 2024-02-08 · 58% similar
SwissSign: modified fields were not saved into certificates and resulted in miss-issuance
#1473971 RESOLVED Certificate Misissuance Opened 2018-07-06 · Closed 2023-02-22 · 53% similar
SwissSign: Domain validated certificate but with stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action