← SwissSign AG cases
Bugzilla #1914023
Self Incident Disclosure
SwissSign: S/MIME LCP not-permitted key usage
RESOLVED
FIXED
SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
SwissSign AG disclosed a compliance failure involving the issuance of two S/MIME LCP certificates with a non-permitted legacy key usage. This issue was identified during an annual audit, prompting the CA to halt the renewal process that allowed the mis-issuance. The affected certificates were revoked before the specified deadline, and the CA has implemented measures to prevent future occurrences, including the removal of the auto-renewal feature and enhancements to their testing procedures. All remediation actions have been completed, and the CA has requested closure of this Bugzilla case.
Chronology
- First mis-issuance of affected S/MIME certificate.
- Last mis-issuance of affected S/MIME certificate.
- Revocation of both affected certificates completed.
- Test coverage for certificate profile changes implemented.
Thread Activity
- SwissSign AG — Posted preliminary incident report detailing the mis-issuance.
- SwissSign AG — Updated that both affected certificates were revoked.
- SwissSign AG — Confirmed implementation of test coverage for profile changes.
- Mozilla representative — Indicated intent to close the case unless further issues arise.
Participants
SwissSign AG
Mozilla representative
External References
Similar Local Cases
SwissSign: MPKI step-up process sets wrong JoI Locality
SwissSign: S/MIME NCP non ASCII symbols in email and SAN field wrong coding
SwissSign: LDAP URL still in CRL distribution point (CDP)
SwissSign: Certificate Profile error for S/MIME MV
SwissSign: duplicate serial number
SwissSign: S/MIME LCP: CN with values other than email address
SwissSign: Certificate with key length 16258
SwissSign: Mis-Issuance of S/MIME certificates