← SwissSign AG cases
Bugzilla #1916489
Certificate Misissuance
SwissSign: LDAP URL still in CRL distribution point (CDP)
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG identified a misissuance of 1,071 TLS certificates due to an outdated LDAP URL in the CRL distribution point, which violated TLS BR regulations effective September 15, 2023. The issue arose during a transition to new CA software, where controls were not applied to the legacy system. All affected certificates were revoked by September 8, 2024. SwissSign has since revised its CA system migration procedures to prevent future occurrences.
Chronology
- TLS BR chapter 7.1.2.11.2 released, requiring 'http' scheme
- Last mis-issuance confirmed
- Investigation into possible misissuance initiated
- Investigation confirms misissuance
- Revocation of affected certificates completed
- CA migration procedure revised
Participants
Sandy Balzer
Ben Wilson
External References
Similar Local Cases
SwissSign: S/MIME LCP not-permitted key usage
SwissSign: difference in upper and lower case between CN field and SAN
SwissSign: Certificate with key length 4098 bit
SwissSign: Misissuance with mispellings in Location for a number of Certificates
SwissSign: Certificate with key length 16258
SwissSign: Mis-Issuance of S/MIME certificates
SwissSign: S/MIME NCP non ASCII symbols in email and SAN field wrong coding
SwissSign: MPKI step-up process sets wrong JoI Locality