← Disig, a.s. cases
Bugzilla #2007132
Certificate Problem Report
Disig: Certificates with invalid embedded SCT signature
RESOLVED
FIXED
Disig, a.s.
AI Summary
Disig identified an issue where four end-user OV certificates contained an invalid embedded SCT signature. All affected certificates were revoked, and an internal investigation was initiated. The root cause was traced to a failure in preserving CT log response data during the final certificate assembly, compounded by a new CT log behavior. Remedial actions included the integration of a linter into the pre-issuance pipeline and strengthening change control processes. The incident has been resolved, and all action items have been completed.
Chronology
- Incident identified and certificates revoked.
- Full incident report delayed.
- Final report submitted and closure requested.
Participants
Jozef Nigut
Peter Miskovic
External References
Similar Local Cases
Disig: TLS certificate with basicConstraints not marked as critical
Disig: Two certificates with same serial number
Disig: Certificates with incorrect Subject attribute order
Disig: Delayed Full Incident Report
Disig: Non-BR-Compliant OCSP Responders
Disig: Missing CA Disig R2I2 Certification Service Full CRL URLs in CCADB
Disig CRL broken, mis-listed? / CA list CRL links need auditing.
Telekom Security: CRL also contained unrevoked certificates