← HARICA cases
Bugzilla #1943596 Certificate Misissuance

HARICA: S/MIME certificate issuance with incorrect commonName

RESOLVED FIXED HARICA
AI Summary

HARICA identified a flaw in their S/MIME certificate issuance workflow where the `organizationName` was incorrectly included in the `commonName` field instead of the expected combination of `givenName` and `surname`. This issue was detected on January 22, 2025, leading to a suspension of certificate issuance until a fix was implemented the following day. A total of 68 mis-issued certificates were identified, with 43 requiring revocation. All affected certificates were revoked by January 31, 2025, and additional unit tests and realistic test vectors were implemented to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:14 UTC Confidence: 1.00
Chronology
  1. Flaw in S/MIME certificate issuance detected.
  2. Fix deployed and certificate issuance resumed.
  3. All affected certificates revoked.
  4. Incident report closure summary submitted.
Participants
Dimitris Zacharopoulos bwilson@mozilla.com
External References
Similar Local Cases
#1943604 RESOLVED Certificate Misissuance Opened 2025-01-24 · Closed 2025-05-25 · 60% similar
HARICA: TLS Server certificate issuance without proper validation
#1597135 RESOLVED Certificate Misissuance Opened 2019-11-17 · Closed 2023-02-22 · 60% similar
HARICA: 3 EV TLS Certificates without L or ST
#1872374 RESOLVED Certificate Misissuance Opened 2023-12-29 · Closed 2024-01-24 · 57% similar
HARICA: subject:organizationIdentifier using VATEL as a prefix for tax identifier
#1696872 RESOLVED Certificate Misissuance Opened 2021-03-08 · Closed 2025-03-20 · 52% similar
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID
#1680083 RESOLVED Certificate Misissuance Opened 2020-12-01 · Closed 2023-02-22 · 51% similar
Camerfirma: certificate with an incorrect OrganizationName
#1736064 RESOLVED Certificate Misissuance Opened 2021-10-15 · Closed 2023-02-22 · 51% similar
Sectigo: Subject field with unvalidated information included in certificates
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 51% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1838371 RESOLVED Certificate Misissuance Opened 2023-06-14 · Closed 2024-01-19 · 50% similar
CFCA: certificate with an incorrect OrganizationName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action