← Agence Nationale de Certification Electronique cases
Bugzilla #1981680 Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Cp Cps Document

TunTrust self-reported OV SSL misissuance involving emailAddress attribute

RESOLVED FIXED Agence Nationale de Certification Electronique
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

TunTrust reported a self-audited compliance issue affecting one OV SSL subscriber certificate. The internal auditor found that the certificate’s Subject included an emailAddress attribute that was not explicitly permitted by the applicable CP/CPS subscriber certificate profile. TunTrust said the certificate was issued on 2025-05-27 and revoked the same day the issue was detected, 2025-08-06. The report states that no other certificates with the same issue were found after checking the hierarchy. TunTrust attributed the problem to configuration drift between the issuance system and the documented CP/CPS profile, and said it updated the system configuration and added validation and audit improvements. The bug was later closed as resolved/fixed.

Model: gpt-5.4-mini Generated: 2026-06-13 12:24 UTC Revised: 2026-07-16 20:48 UTC Confidence: 0.98 14 comments
Chronology
  1. CP/CPS version 01 was approved without the emailAddress attribute in the profile.
  2. Subscriber certificate profile was created in the CA system with the emailAddress attribute.
  3. An OV SSL subscriber certificate with the emailAddress attribute was issued.
  4. An internal auditor detected the non-compliance and the affected certificate was revoked the same day.
  5. TunTrust posted a closure summary describing remediation and commitments.
Thread Activity
  1. Agence Nationale de Certification Electronique — TunTrust opened the bug and said its internal auditor found one non-compliant OV SSL certificate during a quarterly self-audit.
  2. Community commenter — A commenter argued the issue might also indicate RFC 5280 or BR profile problems and suggested a linter weakness.
  3. Google representative — Google said it found only one affected certificate and asked TunTrust to address the points raised in the comment.
  4. Agence Nationale de Certification Electronique — TunTrust filed a full incident report saying the certificate was revoked, no other occurrences were found, and issuance was stopped for non-automation certificates until an action item was put in place.
  5. Google representative — Google asked for more detail on automation, the timeline, the change-control gap, and linting controls.
  6. Agence Nationale de Certification Electronique — TunTrust explained its ACME automation, said the drift came from a 2019 profile setup, and described why the issue was not caught earlier.
  7. Google representative — Google asked follow-up questions about automated validation, annual audits, and the delay in adopting a modern linter.
  8. Agence Nationale de Certification Electronique — TunTrust said it already had automated controls, that the emailAddress setting had been optional, and that PKI Lint adoption was delayed by MPIC and ACME priorities.
  9. Agence Nationale de Certification Electronique — TunTrust posted a closure summary stating the configuration was updated, additional validation checks were implemented, and internal audit procedures were enhanced.
  10. CCADB representative — CCADB issued a final call for comments before closing the report.
Participants
Agence Nationale de Certification Electronique Community commenter Google representative CCADB representative
Similar Local Cases
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 94% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#2009491 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-01-09 · Closed 2026-02-17 · 86% similar
DigiCert: Several non-functioning AIA URLs
#1959721 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-04-10 · Closed 2025-06-12 · 86% similar
Lawtrust: The S/MIME CA’s policy identifiers did not align with the CA/Browser Forum Requirements.
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 86% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#1983955 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-08-19 · Closed 2025-09-15 · 86% similar
Certigna: Subscriber certificate with EKU clientAuth only
#1961406 RESOLVED Certificate Misissuance Opened 2025-04-18 · Closed 2025-07-02 · 85% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1959733 RESOLVED Self Reported Incident Opened 2025-04-10 · Closed 2025-07-16 · 84% similar
CFCA: Failed to respond a Certificate Problem Report within 24 hours which violates Section 4.9.5 of the TLS BRs
#1955365 RESOLVED Self Reported Incident Opened 2025-03-20 · Closed 2025-05-19 · 83% similar
Apple: Public Key Reuse

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action