← HARICA cases
Bugzilla #1943596 Certificate Misissuance Delayed Revocation

HARICA: S/MIME certificate issuance with incorrect commonName

RESOLVED FIXED HARICA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

HARICA reported a self-discovered incident in which a recently deployed S/MIME SV certificate issuance workflow populated the certificate subject `commonName` with the `organizationName` value instead of the concatenation of `givenName` and `surname`. HARICA became aware of the issue on 2025-01-22 after receiving an email from a subscriber who used the new “bulk Enterprise S/MIME SV certificate request” process and observed the incorrect `commonName`. HARICA suspended S/MIME certificate issuance until a patch was deployed on 2025-01-23, after which issuance resumed. HARICA identified 68 mis-issued certificates (43 non-expired, non-revoked) and revoked affected certificates, with a note that delayed revocation for some remaining certificates was handled in a separate bug (Bug 1945389). HARICA also implemented remediation including additional unit tests and added realistic test vectors to the test process. Mozilla indicated it would close the bug after follow-up questions, and HARICA requested closure via an incident closure summary.

Model: gpt-5.4-nano Generated: 2026-06-13 21:14 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.90 9 comments
Chronology
  1. HARICA discovered that SV S/MIME certificates were issued with an incorrect subject commonName value due to a flaw in the bulk issuance workflow.
  2. HARICA deployed a patch fixing the workflow and resumed SV S/MIME certificate issuance.
  3. HARICA informed subscribers of upcoming revocation for affected active certificates.
  4. HARICA revoked remaining affected certificates, with delayed revocation issues addressed in a separate bug.
  5. HARICA completed adding realistic test vectors to the test process.
  6. HARICA completed unit test implementations for SV S/MIME commonName correctness.
  7. HARICA submitted an incident closure summary requesting closure of the bug.
Thread Activity
  1. HARICA — Filed a preliminary incident report describing the incorrect commonName behavior, issuance suspension, planned revocation, subscriber notification, and a commitment to post a full incident report by 2025-01-31.
  2. HARICA — Posted the full incident report with root cause analysis, impact (68 mis-issued certificates; 43 scheduled for revocation within 5 days), the timeline, and lessons learned including that some certificates were not revoked by the pre-determined timeline.
  3. HARICA — Reported preparation of internal documentation requiring realistic testing values.
  4. HARICA — Confirmed completion of internal documentation with realistic testing values and updated action items and due dates.
  5. HARICA — Provided a status update that unit tests for commonName correctness were being prepared and requested setting the next update to 2025-04-01.
  6. HARICA — Reported completion of all pending action items and asked to close if there were no further questions.
  7. Mozilla representative — Asked whether there were follow-up questions or requests and indicated HARICA should file an incident closure summary to close the bug.
  8. HARICA — Submitted an incident report closure summary, stating remediation steps (revocation and subscriber contact) and requesting closure; noted delayed revocation for remaining certificates was separately addressed in Bug 1945389.
  9. Mozilla representative — Indicated the bug would be closed next Wednesday (23-Apr-2025) unless there were questions or issues.
Participants
HARICA Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1699796 RESOLVED Self Reported Incident Certificate Misissuance Opened 2021-03-19 · Closed 2023-02-22 · 97% similar
HARICA: Certificates with invalid policy tree
#1872374 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-12-29 · Closed 2026-06-10 · 88% similar
HARICA: subject:organizationIdentifier using VATEL as a prefix for tax identifier
#1535509 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 87% similar
HARICA: Insufficient serial number entropy
#1535772 RESOLVED Incident Certificate Misissuance Revocation Issue Opened 2019-03-15 · Closed 2023-02-22 · 87% similar
HARICA: wrong characters in NC extension of Technically Constrained Intermediate CA Certificates
#1951415 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-03-03 · Closed 2025-05-08 · 86% similar
Chunghwa Telecom: Failure to check restrictive CAA record during Migration
#2017845 RESOLVED Certificate Misissuance Self Reported Incident Problem Reporting Failure Opened 2026-02-19 · Closed 2026-06-29 · 82% similar
HARICA: Incorrect nCAId in PSD2 QCStatement for QWACs
#1896108 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-05-10 · Closed 2024-09-06 · 79% similar
Telia: Certificates Issued with lower case value in subject:countryName
#1597135 RESOLVED Certificate Misissuance Revocation Issue Incident Opened 2019-11-17 · Closed 2023-02-22 · 79% similar
HARICA: 3 EV TLS Certificates without L or ST

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action