← SwissSign AG cases
Bugzilla #1929189 Certificate Misissuance

SwissSign: S/MIME certificates deviate from CPR

CLOSED FIXED SwissSign AG
AI Summary

SwissSign AG reported a misissuance of 30,967 sponsor-validated S/MIME certificates due to a deviation between the certificate profile in their public documents and the issued certificates. The issue arose from a misunderstanding regarding key usage combinations allowed in the certificates, which led to the issuance of certificates that did not comply with the Certificate Policy Requirements (CPR). All affected certificates were revoked promptly, and the CPR was updated to reflect the correct profile. Additionally, a new automation system was implemented to prevent future discrepancies.

Model: gpt-4o-mini Generated: 2026-06-13 20:48 UTC Confidence: 0.95
Chronology
  1. Introduction of the new S/MIME NCP extended profile and publication of version 6 of the SwissSign CPR S/MIME
  2. Start issuing of Sponsor-validated S/MIME certificates according to updated CPR
  3. Revocation of all affected certificates completed
  4. CPR updated to mark the profile for ICA 2022-1 as retired
  5. Go-live with CPR automation after successful audit
Participants
Mike Guenther Roman Fischer Stephan Verbuecheln
Similar Local Cases
#1851164 RESOLVED Certificate Misissuance Opened 2023-09-01 · Closed 2023-09-22 · 70% similar
SwissSign: S/MIME wrong key Usage
#1848854 RESOLVED Certificate Misissuance Opened 2023-08-15 · Closed 2024-03-27 · 66% similar
SwissSign: S/MIME LCP: CN with values other than email address
#1849364 RESOLVED Certificate Misissuance Opened 2023-08-18 · Closed 2023-09-22 · 66% similar
SwissSign: Missed revocation and opening Bugzilla
#1766255 RESOLVED Certificate Misissuance Opened 2022-04-25 · Closed 2023-02-22 · 63% similar
SwissSign: Mis-Issuance of S/MIME certificates
#1691704 RESOLVED Certificate Misissuance Opened 2021-02-09 · Closed 2023-02-22 · 62% similar
SwissSign: Certificate with key length 4098 bit
#1866091 RESOLVED Certificate Misissuance Opened 2023-11-22 · Closed 2023-12-11 · 60% similar
SwissSign: EV JurisdictionStateOrProvinceName - one certificate not selected for revocation
#1731586 RESOLVED Certificate Misissuance Opened 2021-09-20 · Closed 2023-02-22 · 59% similar
SwissSign: Certificate with key length 16258
#1894054 RESOLVED Certificate Misissuance Opened 2024-04-29 · Closed 2024-07-03 · 59% similar
SwissSign: MPKI step-up process sets wrong JoI Locality

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action