← eMudhra Technologies Limited cases
Bugzilla #1970728 Security Incident

eMudhra: Invalid CRL signatures

RESOLVED FIXED eMudhra Technologies Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On June 5, 2025, eMudhra was alerted by Mozilla's monitoring service regarding six Certificate Revocation Lists (CRLs) that were published with invalid ECDSA signatures due to incorrect private key usage. The issue was initially reported by Sectigo via email on June 3, but the message was quarantined and not seen until June 5. eMudhra investigated and confirmed the problem, publishing corrected CRLs on June 6. A full incident report was submitted, detailing the root cause as a manual process error and outlining remediation steps, including transitioning to an automated CRL signing process. All corrective actions were completed by June 20, 2025.

Model: gpt-4o-mini Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 18:41 UTC Confidence: 0.85 16 comments
Chronology
  1. CRLs generated and published with incorrect key configuration
  2. Correct CRLs published after validation
Thread Activity
  1. Sectigo — Reported invalid CRL signatures for eMudhra.
  2. Emudhra representative — Submitted preliminary incident report acknowledging the issue.
  3. Emudhra representative — Provided full incident report detailing the root cause and remediation.
  4. Emudhra representative — Confirmed completion of all action items related to the incident.
  5. Emudhra representative — Requested closure of the incident report.
Participants
Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1689589 RESOLVED Self Reported Incident Security Incident Opened 2021-01-29 · Closed 2023-02-22 · 61% similar
Telia: Disallowed curve (P-521) in leaf certificate
#2012157 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2026-01-23 · Closed 2026-03-08 · 61% similar
Actalis: Issuance of certificate using keys previously reported as compromised
#1965828 RESOLVED Self Reported Incident Security Incident Opened 2025-05-12 · Closed 2025-08-19 · 60% similar
SwissSign: OCSP outage
#1577014 RESOLVED Security Incident Opened 2019-08-27 · Closed 2023-02-22 · 60% similar
DigiCert: OCSP services returns 1 byte
#1999296 RESOLVED Security Incident Opened 2025-11-10 · Closed 2025-12-29 · 60% similar
Telia: Findings in 2025 ETSI Audit - Incident Report #1 – Vulnerability management
#1446121 RESOLVED Self Reported Incident Security Incident Opened 2018-03-15 · Closed 2023-02-22 · 60% similar
IdenTrust: Improper encoding of wildcard certificate
#1882904 RESOLVED Security Incident Opened 2024-02-29 · Closed 2025-02-12 · 60% similar
Google Trust Services: Incorrect OCSP responses for new ICAs under test
#1820269 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-03-03 · Closed 2024-06-30 · 59% similar
DigiCert: 4 CRLs unavailable or not responding

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action