TunTrust self-reported OV SSL misissuance involving emailAddress attribute
TunTrust reported a self-audited compliance issue affecting one OV SSL subscriber certificate. The internal auditor found that the certificate’s Subject included an emailAddress attribute that was not explicitly permitted by the applicable CP/CPS subscriber certificate profile. TunTrust said the certificate was issued on 2025-05-27 and revoked the same day the issue was detected, 2025-08-06. The report states that no other certificates with the same issue were found after checking the hierarchy. TunTrust attributed the problem to configuration drift between the issuance system and the documented CP/CPS profile, and said it updated the system configuration and added validation and audit improvements. The bug was later closed as resolved/fixed.
- CP/CPS version 01 was approved without the emailAddress attribute in the profile.
- Subscriber certificate profile was created in the CA system with the emailAddress attribute.
- An OV SSL subscriber certificate with the emailAddress attribute was issued.
- An internal auditor detected the non-compliance and the affected certificate was revoked the same day.
- TunTrust posted a closure summary describing remediation and commitments.
- Agence Nationale de Certification Electronique — TunTrust opened the bug and said its internal auditor found one non-compliant OV SSL certificate during a quarterly self-audit.
- Community commenter — A commenter argued the issue might also indicate RFC 5280 or BR profile problems and suggested a linter weakness.
- Google representative — Google said it found only one affected certificate and asked TunTrust to address the points raised in the comment.
- Agence Nationale de Certification Electronique — TunTrust filed a full incident report saying the certificate was revoked, no other occurrences were found, and issuance was stopped for non-automation certificates until an action item was put in place.
- Google representative — Google asked for more detail on automation, the timeline, the change-control gap, and linting controls.
- Agence Nationale de Certification Electronique — TunTrust explained its ACME automation, said the drift came from a 2019 profile setup, and described why the issue was not caught earlier.
- Google representative — Google asked follow-up questions about automated validation, annual audits, and the delay in adopting a modern linter.
- Agence Nationale de Certification Electronique — TunTrust said it already had automated controls, that the emailAddress setting had been optional, and that PKI Lint adoption was delayed by MPIC and ACME priorities.
- Agence Nationale de Certification Electronique — TunTrust posted a closure summary stating the configuration was updated, additional validation checks were implemented, and internal audit procedures were enhanced.
- CCADB representative — CCADB issued a final call for comments before closing the report.