← Financijska agencija (Fina) cases
Bugzilla #1986968
Certificate Misissuance
Financijska agencija (Fina): Mis-issued certificates
RESOLVED
FIXED
Financijska agencija (Fina)
AI Summary
Financijska agencija (Fina) issued certificates for two well-known IP addresses and for non-existent domains, which were intended solely for internal testing. The incident was reported by Microsoft’s Trusted Root Program, prompting an investigation that revealed the certificates were issued without proper verification. All affected certificates were revoked, and the private keys were destroyed. Fina has since implemented corrective measures, including revising their procedures for issuing test certificates and enhancing staff training to prevent future occurrences.
Chronology
- Initial report of mis-issued certificates received from Microsoft.
- Affected certificates revoked and private keys destroyed.
- Full incident report submitted.
- Stage 2 of eIDAS conformity assessment audit began.
- Conformity Assessment Report received.
- Closure report submitted.
Participants
miroslav.perincic@fina.hr
cku@heise.de
stephan@verbuecheln.ch
zhangyoufu@gmail.com
pete@cooperjr.name
bwilson@mozilla.com
malcolm.doody@gmail.com
daniel@binaryparadox.net
martijn.katerbarg@sectigo.com
External References
Similar Local Cases
IdenTrust: unintended creation of a Root CA certificate
SSL.com: S/MIME certificates issued prior to validation
iTrusChina: Issuance of certificates using keys previously reported as compromised
GoDaddy: Misissuance of Cross Signed Certs
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
SSL.com: Wildcard DV certificate issued with a non-validated domain name
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
PostSignum: Mis-issued certificate