Telia: S/MIME Misissuance incorrect AIA id-ca-caIssuer http:URI
Telia CA reported a misissuance incident involving two S/MIME certificates that violated the S/MIME Baseline Requirements regarding the Authority Information Access (AIA) extension. The issue was identified on May 9, 2025, during a routine linting check, which revealed that the AIA contained an incorrect URI. Telia CA promptly revoked both certificates and initiated an internal investigation. A full incident report was subsequently prepared, detailing the root causes and remediation steps taken, including the implementation of custom pre-issuance linting to prevent future occurrences. The incident was disclosed to relevant root programs, and all action items have been completed as of July 2025.
- Telia CA issued two S/MIME certificates with incorrect AIA extension.
- Misissuance identified and certificates revoked.
- Full incident report planned for disclosure.
- Final call for comments on the incident report.
- Incident report closure anticipated.
- Teliacompany representative — Preliminary incident report disclosed detailing the misissuance.
- Teliacompany representative — Full incident report posted with detailed analysis and remediation steps.
- Teliacompany representative — Update provided, awaiting closure of the incident report.