Telia: S/MIME Certificate issued to expired domain
Telia Certificate Authority (Telia CA) issued a Legacy OV S/MIME certificate for a domain that had expired validation. Upon discovering the issue during a routine log review, Telia CA promptly revoked the affected certificate and disabled the subscriber's API to prevent further misissuance. A preliminary incident report was submitted, followed by a full report detailing the root cause, which was attributed to a manual configuration error that overlooked the domain validation reuse threshold. Telia CA has committed to improving its configuration management processes to prevent similar incidents in the future. The case has been resolved with all action items completed.
- Telia CA issued a Legacy OV S/MIME certificate for a domain with expired validation.
- The case was resolved and all action items were completed.
- Teliacompany representative — Preliminary incident report submitted regarding the issuance of a certificate for an expired domain.
- Teliacompany representative — Full incident report submitted detailing the misissuance and its impact.
- Teliacompany representative — Provided incident report closure summary as requested.
- Mozilla representative — Confirmed closure of the case on December 6, 2024.