SwissSign: Attribute Change process did not revoke single-domain certificates
SwissSign AG reported an incident where their system failed to revoke single-domain OV TLS certificates during an attribute change process. This issue was triggered by customer feedback on 2025-10-07, leading to an investigation that confirmed the failure to send revocation emails and perform necessary revocations. The CA suspended the attribute change procedure and initiated a root cause analysis, which revealed that an update to their pricing model caused links to be incorrectly overwritten. The incident was resolved with corrective actions implemented by 2025-10-21, and a final incident report was submitted on 2025-12-04.
- Attribute change initiated, leading to customer inquiries.
- Compliance team escalated the issue after confirming the failure.
- Non-compliance ended after corrective actions were implemented.
- Final incident report submitted and closure requested.
- SwissSign AG — Preliminary incident report submitted detailing the issue.
- SwissSign AG — Full incident report provided with detailed analysis and corrective actions.
- SwissSign AG — Closure summary report submitted, detailing remediation and commitment to prevent future issues.