← Agence Nationale de Certification Electronique cases
Bugzilla #1981680
Certificate Misissuance
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
RESOLVED
Agence Nationale de Certification Electronique
AI Summary
TunTrust identified a mis-issuance of an OV SSL certificate that included an 'emailAddress' attribute not permitted by its certificate profile. The issue was detected during a self-audit on August 6, 2025, leading to the immediate revocation of the affected certificate issued on May 27, 2025. A thorough review confirmed no other certificates were affected. The incident highlighted a configuration drift between the issuance system and the documented certificate profile, prompting updates to validation checks and internal audit procedures.
Chronology
- Subscriber certificate with emailAddress attribute issued.
- Non-compliance detected and certificate revoked.
Participants
pki@tuntrust.tn
rowleylaw@gmail.com
chrome-root-program@google.com
incident-reporting@ccadb.org
External References
Similar Local Cases
OATI: Misissuance detected by PKIMetal
Firmaprofesional: Misissuance of TLS Subordinate CA "AC Firmaprofesional - Secure Web 2024"
CCA India: Misissuance detected by PKIMetal
PostSignum: Mis-issued certificate
Actalis: Issuance of certificate using keys previously reported as compromised
Government of Korea: Misissuance detected by PKIMetal
VISA: Misissuance detected by PKIMetal
DigiCert: Misissuance detected by PKIMetal