← Microsec Ltd. cases
Bugzilla #1952519 Self Reported Incident Repository Issue

Microsec: Inconsistent Disclosure of S/MIME BR Audit Information in CCADB

RESOLVED FIXED Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsec Ltd. reported an issue regarding the inconsistent disclosure of S/MIME BR audit information in the Common CA Database (CCADB). The problem was identified when a doppelganger root certificate record did not specify any S/MIME BR audit details, which is required by Mozilla, Apple, and Microsoft policies. The issue was triggered by an email from Rob Stradling highlighting the problem. Microsec conducted an investigation and proposed the removal of the duplicate root certificate from CCADB. After discussions with CCADB support, the issue was resolved by updating the CCADB record with the necessary audit information. The bug was subsequently closed as invalid.

Model: gpt-4o-mini Generated: 2026-06-13 21:16 UTC Revised: 2026-06-16 19:18 UTC Confidence: 0.90 14 comments
Chronology
  1. Rob Stradling reported the issue to the CCADB public mailing list.
  2. Microsec submitted the updated CCADB record to the Root Store.
  3. The bug was closed as invalid after the CCADB record was updated.
Thread Activity
  1. Microsec representative — Microsec opened the incident bug in Bugzilla.
  2. Microsec representative — CCADB Support responded and planned to discuss the issue.
  3. Mozilla representative — The case has been processed in CCADB.
  4. Microsec representative — Microsec confirmed no audit report issue for their certificates.
  5. CCADB representative — Final call for comments on the incident report.
Participants
Microsec representative Stradling representative Mozilla representative Community commenter CCADB representative
Similar Local Cases
#1622539 RESOLVED Self Reported Incident Opened 2020-03-14 · Closed 2023-02-22 · 80% similar
Microsec: Issuance of 2 IVCP precertificates without givenName, surName, localityName fields
#1925239 RESOLVED Self Reported Incident Opened 2024-10-17 · Closed 2025-01-14 · 79% similar
Microsec: Expired Certificates on test Pages for Revocation
#1865880 RESOLVED Self Reported Incident Opened 2023-11-21 · Closed 2024-02-14 · 78% similar
Microsec: Findings in 2023 Audit
#2005939 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-12-14 · Closed 2026-03-13 · 78% similar
Microsec: CT Logging mistakes
#2013576 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-01-30 · Closed 2026-02-27 · 77% similar
Microsec: "DV valid" test website certificate issued under incorrect root
#1549861 RESOLVED Repository Issue Self Reported Incident Opened 2019-05-07 · Closed 2023-02-22 · 70% similar
Camerfirma: Outdated audit statements for intermediate certs
#1925293 RESOLVED Repository Issue Self Reported Incident Opened 2024-10-17 · Closed 2025-02-28 · 69% similar
Firmaprofesional: Incorrect publication of information for "Test Website - Revoked" URL in the CCADB.
#1572234 RESOLVED Self Reported Incident Repository Issue Opened 2019-08-07 · Closed 2023-02-22 · 68% similar
GoDaddy: cross certificate disclosure to CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action