← HARICA cases
Bugzilla #1943604 Certificate Misissuance

HARICA: TLS Server certificate issuance without proper validation

CLOSED FIXED HARICA
AI Summary

On January 23, 2025, HARICA was notified of a TLS Server certificate issued without proper domain control validation due to a typo in the domain name. The validation system incorrectly reused domain control validation (DCV) evidence based on substring matching, allowing the misissuance. HARICA suspended TLS certificate issuance immediately, revoked the affected certificate within 24 hours, and confirmed no other certificates were impacted. A patch was implemented to prevent similar issues in the future, and a comprehensive review of the validation process was initiated.

Model: gpt-4o-mini Generated: 2026-06-13 21:15 UTC Confidence: 1.00
Chronology
  1. HARICA informed of misissued TLS certificate.
  2. Certificate issuance suspended and affected certificate revoked.
  3. Patch deployed to fix validation logic.
  4. Incident closure summary submitted.
Participants
Dimitris Zacharopoulos
External References
Similar Local Cases
#1943596 RESOLVED Certificate Misissuance Opened 2025-01-24 · Closed 2025-05-01 · 60% similar
HARICA: S/MIME certificate issuance with incorrect commonName
#1597135 RESOLVED Certificate Misissuance Opened 2019-11-17 · Closed 2023-02-22 · 59% similar
HARICA: 3 EV TLS Certificates without L or ST
#1872374 RESOLVED Certificate Misissuance Opened 2023-12-29 · Closed 2024-01-24 · 55% similar
HARICA: subject:organizationIdentifier using VATEL as a prefix for tax identifier
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 45% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1531817 RESOLVED Certificate Misissuance Opened 2019-03-01 · Closed 2023-02-22 · 44% similar
DigiCert: in-addr.arpa Misissuance
#1524567 RESOLVED Certificate Misissuance Opened 2019-02-01 · Closed 2023-02-22 · 43% similar
Telia: invalid IP value in SAN DNS field
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 43% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1908128 RESOLVED Certificate Misissuance Opened 2024-07-16 · Closed 2024-08-28 · 43% similar
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action