← LAWtrust cases
Bugzilla #1959721 Self Reported Incident Certificate Misissuance

Lawtrust: The S/MIME CA’s policy identifiers did not align with the CA/Browser Forum Requirements.

RESOLVED FIXED LAWtrust
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Lawtrust's disclosure of a compliance issue regarding their S/MIME certificate policy identifiers, which did not align with the CA/Browser Forum Requirements. The issue was identified during a WebTrust audit, where it was found that the CA had issued internal test certificates with incorrect policy identifiers and a non-compliant Distinguished Name (DN) structure. Following the identification of the issue on December 3, 2024, Lawtrust revoked the affected certificates on March 13, 2025, after confirming the necessary changes with auditors. The CA has since updated its certificate profiles and implemented new procedures to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:11 UTC Revised: 2026-06-16 19:10 UTC Confidence: 0.85 15 comments
Chronology
  1. First S/MIME Test Certificate pair issued.
  2. Non-compliance identified regarding policy identifiers.
  3. Affected certificates revoked.
  4. Incident report closure requested.
Thread Activity
  1. Altron representative — Created attachment detailing audit findings regarding policy identifiers.
  2. Sectigo — Requested clarification on whether there were one or two incidents related to policy identifiers.
  3. Altron representative — Provided updates on the incident report and changes made to certificate profiles.
  4. Altron representative — Submitted closure summary detailing root causes and remediation actions.
Participants
Altron representative Community commenter Sectigo Google representative CCADB representative
External References
Similar Local Cases
#1981680 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2025-08-07 · Closed 2025-09-26 · 86% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
#2032482 ASSIGNED Ca Certificate Compliance Certificate Misissuance Problem Reporting Failure Audit Finding Opened 2026-04-16 Still Open · 84% similar
OATI: Misissuance detected by PKIMetal
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 83% similar
Financijska agencija (Fina): Mis-issued certificates
#1996857 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-10-28 · Closed 2025-12-11 · 81% similar
IZENPE: not allowed Key Usage in ocsp responder certificate
#2007070 RESOLVED Certificate Misissuance Opened 2025-12-19 · Closed 2026-03-30 · 79% similar
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 79% similar
IdenTrust: Cross-signed root certificate mis-issuance
#1965459 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-05-09 · Closed 2025-10-31 · 79% similar
Telia: S/MIME Misissuance incorrect AIA id-ca-caIssuer http:URI
#2007070 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2025-12-19 · Closed 2026-03-30 · 79% similar
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action