← eMudhra Technologies Limited cases
Bugzilla #1973341 Policy Document Issue Certificate Misissuance

eMudhra emSign PKI Services: Policy Document Inconsistency

RESOLVED FIXED eMudhra Technologies Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

eMudhra Technologies Limited reported an incident involving the issuance of a TLS certificate for CN=msmeranchi.nic.in with an RSA key size of 4048 bits. This issuance was based on a CSR from the subscriber and was compliant with the CA/Browser Forum Baseline Requirements, which only specify a minimum key size of 2048 bits. However, the CA's Certificate Policy/Certification Practice Statement (CP/CPS) versions v1.14 and v1.19 only referenced RSA 2048, leading to ambiguity regarding larger key sizes. The issue was identified by an external researcher on June 19, 2025, prompting eMudhra to acknowledge the inconsistency and plan corrective actions, including updating their CP/CPS to clarify acceptable key sizes. All 449 unexpired certificates that did not comply with the updated policy were subsequently revoked. The CP/CPS was revised and published on July 8, 2025.

Model: gpt-4o-mini Generated: 2026-06-13 21:30 UTC Revised: 2026-06-16 18:42 UTC Confidence: 0.85 16 comments
Chronology
  1. Certificate issued for CN=msmeranchi.nic.in with an RSA key size of 4048 bits.
  2. External researcher reported the issue regarding key size documentation.
  3. Non-compliance period ended with the initiation of remediation.
  4. Revised CP/CPS v1.20 published to clarify acceptable RSA key sizes.
  5. Final call for comments on the incident report before closure.
Thread Activity
  1. Emudhra representative — Preliminary incident report submitted detailing the inconsistency in key size documentation.
  2. Sectigo — Provided feedback on the need for clarity in documentation regarding key sizes.
  3. Emudhra representative — Confirmed that all unexpired certificates identified in the incident were revoked.
  4. CCADB representative — Final call for comments on the incident report before closure.
Participants
Emudhra representative Sectigo Community commenter
External References
Similar Local Cases
#1929189 RESOLVED Certificate Misissuance Policy Document Issue Opened 2024-11-05 · Closed 2025-07-01 · 71% similar
SwissSign: S/MIME certificates deviate from CPR
#1836694 RESOLVED Certificate Misissuance Policy Document Issue Opened 2023-06-05 · Closed 2023-09-29 · 70% similar
Hongkong Post: Invalid EV cert businessCategory
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 64% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 64% similar
Certigna: TLS certificates with Basic constraint non-critical
#1705480 RESOLVED Ca Documents Policy Document Issue Opened 2021-04-15 · Closed 2023-02-22 · 63% similar
SECOM: CP/CPS does not clearly specify domain validation methods
#1693930 RESOLVED Policy Document Issue Opened 2021-02-20 · Closed 2023-02-22 · 63% similar
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
#1467414 RESOLVED Certificate Misissuance Self Reported Incident Opened 2018-06-07 · Closed 2023-02-22 · 63% similar
GDCA: Misissuance of certificates with small RSA keys
#1717357 RESOLVED Certificate Misissuance Incident Opened 2021-06-20 · Closed 2023-02-22 · 63% similar
Actalis: Issuance of intermediates after 2020-08-20 that do not comply with Mozilla Policy and the Baseline Requirements

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action