SwissSign: LDAP URL still in CRL distribution point (CDP)
SwissSign AG disclosed a compliance issue involving the issuance of 1,071 misissued TLS certificates, which included an LDAP URL in the CRL distribution point, contrary to the updated TLS Baseline Requirements effective September 15, 2023. The issue was discovered following a private recommendation to investigate certificates, leading to an internal review that confirmed the misissuance. SwissSign has scheduled the revocation of the affected certificates for September 8, 2024, and has completed the revocation process on time. A root cause analysis identified that the error stemmed from a lack of synchronization between the phaseout of the old CA software and regulatory changes. SwissSign has since revised its CA system migration procedures to prevent future occurrences.
- Revocation of all affected certificates completed.
- SwissSign AG — Posted initial incident report confirming misissuance of certificates.
- SwissSign AG — Updated status indicating all affected certificates have been revoked.
- SwissSign AG — Revised CA migration procedure to include explicit controls.
- SwissSign AG — Requested closure of the Bugzilla case unless further questions arise.