← Telia Company cases
Bugzilla #1965459
Certificate Misissuance
Telia: S/MIME Misissuance incorrect AIA id-ca-caIssuer http:URI
RESOLVED
FIXED
Telia Company
AI Summary
Telia CA issued two S/MIME certificates that violated S/MIME Baseline Requirements regarding the Authority Information Access (AIA) extension. The misissuance was identified shortly after issuance, leading to the immediate revocation of both certificates. The root causes included reliance on incorrect values from a certificate signing request and insufficient validation processes. Telia has since implemented corrective measures, including custom pre-issuance linting and policy updates to prevent recurrence of similar issues.
Chronology
- CSR request received for the first certificate
- Misissuance identified and certificates revoked
- Full incident report disclosed
- Final call for comments on incident report
Participants
Antti Backman
External References
Similar Local Cases
Telia: TLS incorrect AIA caIssuer URI and incorrect CDP
Telia: S/MIME Certificate issued to expired domain
Telia: TLS certificates issued in violation of TLS BR v2.0.1
Telia: S/MIME certificates issued in violation of S/MIME BR v1.0.1
Telia: Certificates Issued with lower case value in subject:countryName
Telia: S/MIME Misissuance - incorrect subject information for Multipurpose sponsor-validated-profile
Telia: "Some-State" in stateOrProvinceName
Telia: invalid IP value in SAN DNS field