← HARICA cases
Bugzilla #1942130 Ca Certificate Compliance Certificate Misissuance

HARICA: S/MIME mailbox-validated certificates issued without proper email validation

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA reported an incident after receiving a certificate problem report from a subscriber about HARICA S/MIME certificate issuance. The subscriber stated that a flaw in the S/MIME workflow permitted issuance of mailbox-validated certificates without proper validation of the email address. HARICA said the flaw was introduced in the REST API offered by the HARICA RA on 2025-01-08 09:24 and affected only mailbox-validated S/MIME certificates; other validation levels and other certificate types were not impacted. After reproducing the issue, HARICA stopped certificate issuance, developed and deployed an urgent patch to reinstate the missing email validation, and revoked five non-expired, non-revoked misissued certificates within 24 hours. HARICA also refactored the RA code to add a central checkpoint before S/MIME and TLS certificate issuance to ensure required validations are completed successfully, and to verify that pre-validated organization requests include all labels of the pre-validated base domain names. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it would close the incident on 23-Apr-2025 unless there were items to discuss.

Model: gpt-5.4-nano Generated: 2026-06-13 21:14 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.86 7 comments
Chronology
  1. HARICA received a subscriber report about S/MIME mailbox-validated certificates being issued without proper email validation and stopped issuance while responding.
  2. HARICA deployed an urgent patch and revoked five misissued mailbox-validated S/MIME certificates within 24 hours.
  3. HARICA completed refactoring action items to add central validation checks and pre-validated organization domain label matching before issuance.
  4. Mozilla indicated it would close the bug on 23-Apr-2025 unless there were remaining discussion items.
Thread Activity
  1. HARICA — HARICA described a preliminary incident report: a subscriber reported that a REST API flaw allowed mailbox-validated S/MIME certificates without proper email validation, and HARICA said it patched the issue and revoked five misissued certificates within 24 hours.
  2. HARICA — HARICA posted the full incident report with impact, timeline, and root cause analysis, including that the problematic code appeared only in mailbox-validated S/MIME certificates.
  3. HARICA — HARICA requested the next update be set for 2025-03-11 to provide progress on remaining action items.
  4. HARICA — HARICA provided a status update describing designs for central validation cross-checking before certificate issuance and central domain-label matching for pre-validated organizations.
  5. HARICA — HARICA reported that all pending action items were completed as of 2025-03-21 and asked to close the incident.
  6. HARICA — HARICA posted an incident report closure summary stating the patch and revocations were completed and that the RA code was refactored to add central validation and pre-validated domain label checks.
  7. Mozilla representative — Mozilla stated it would close the bug next Wednesday, 23-Apr-2025, unless there were items to discuss.
Participants
HARICA Mozilla representative
External References
Similar Local Cases
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 80% similar
KIR S.A.: Invalid organizationName
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 79% similar
HARICA: Certificates with invalid policy tree
#1943596 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-01-24 · Closed 2025-05-01 · 79% similar
HARICA: S/MIME certificate issuance with incorrect commonName
#2049237 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Revocation Issue Opened 2026-06-22 Still Open · 78% similar
HARICA: Continued issuance and refusal to revoke TLS certificates for EU-sanctioned blocked entities (Sberbank, VTB, KAMAZ, ANO Dialog)
#1793441 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-10-03 · Closed 2023-02-22 · 78% similar
GlobalSign: CRL contains invalid signature algorithm
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 78% similar
DigiCert: Invalid localityName
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 78% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 77% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action