← SwissSign AG cases
Bugzilla #1914023 Certificate Misissuance

SwissSign: S/MIME LCP not-permitted key usage

RESOLVED FIXED SwissSign AG
AI Summary

SwissSign AG reported a mis-issuance of two S/MIME LCP certificates due to the use of a legacy profile during the renewal process, resulting in non-permitted key usage. The issue was identified during an annual audit, leading to the immediate suspension of the email-based renewal process and the revocation of the affected certificates. All remediation actions have been completed, including the removal of the auto-renewal feature and the implementation of additional test coverage to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 20:49 UTC Confidence: 1.00
Chronology
  1. First mis-issuance detected
  2. Last mis-issuance detected
  3. Bugzilla case posted
  4. Both affected certificates revoked
  5. Test coverage for profile changes implemented
Participants
Sandy Balzer Ben Wilson
External References
Similar Local Cases
#1766255 RESOLVED Certificate Misissuance Opened 2022-04-25 · Closed 2023-02-22 · 68% similar
SwissSign: Mis-Issuance of S/MIME certificates
#1874196 RESOLVED Certificate Misissuance Opened 2024-01-11 · Closed 2024-03-27 · 68% similar
SwissSign: difference in upper and lower case between CN field and SAN
#1916489 RESOLVED Certificate Misissuance Opened 2024-09-03 · Closed 2025-03-18 · 68% similar
SwissSign: LDAP URL still in CRL distribution point (CDP)
#1848854 RESOLVED Certificate Misissuance Opened 2023-08-15 · Closed 2024-03-27 · 63% similar
SwissSign: S/MIME LCP: CN with values other than email address
#1613334 RESOLVED Certificate Misissuance Opened 2020-02-05 · Closed 2023-02-22 · 61% similar
SwissSign: Misissuance with mispellings in Location for a number of Certificates
#1731586 RESOLVED Certificate Misissuance Opened 2021-09-20 · Closed 2023-02-22 · 61% similar
SwissSign: Certificate with key length 16258
#1914020 RESOLVED Certificate Misissuance Opened 2024-08-20 · Closed 2024-09-13 · 61% similar
SwissSign: S/MIME NCP non ASCII symbols in email and SAN field wrong coding
#1894054 RESOLVED Certificate Misissuance Opened 2024-04-29 · Closed 2024-07-03 · 61% similar
SwissSign: MPKI step-up process sets wrong JoI Locality

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action