← Disig, a.s. cases
Bugzilla #2007132 Certificate Misissuance Self Reported Incident

Disig: Certificates with invalid embedded SCT signature

RESOLVED FIXED Disig, a.s.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Disig, a CA, discovered that four end-user OV certificates contained an invalid embedded Signed Certificate Timestamp (SCT) signature. Following this internal investigation, all affected certificates were revoked. A full incident report was initiated, detailing the root cause as a failure to preserve CT log response data during certificate assembly. Disig has implemented corrective actions, including the removal of the problematic CT log server from their active submission list and the integration of a new linter into their pre-issuance pipeline to prevent future occurrences. The incident is now resolved with all action items completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 18:39 UTC Confidence: 0.85 15 comments
Chronology
  1. Disig identified invalid SCT signatures in four OV certificates and revoked them.
Thread Activity
  1. Disig, a.s. — Preliminary Incident Report submitted detailing the invalid SCT signatures.
  2. Disig, a.s. — Full Incident Report provided with a timeline and root cause analysis.
  3. Disig, a.s. — Report Closure Summary submitted, confirming all action items have been completed.
Participants
Disig, a.s. CCADB representative Mm representative
Similar Local Cases
#1888104 RESOLVED Certificate Misissuance Opened 2024-03-27 · Closed 2024-07-11 · 99% similar
Disig: TLS certificate with basicConstraints not marked as critical
#2008972 RESOLVED Self Reported Incident Opened 2026-01-07 · Closed 2026-01-28 · 96% similar
Disig: Delayed Full Incident Report
#1390991 RESOLVED Ca Certificate Compliance Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 94% similar
Disig: Non-BR-Compliant Certificate Issuance
#1889672 RESOLVED Certificate Misissuance Opened 2024-04-04 · Closed 2024-06-01 · 91% similar
Disig: Certificates with incorrect Subject attribute order
#1907667 RESOLVED Certificate Misissuance Opened 2024-07-12 · Closed 2024-08-17 · 89% similar
Disig: Two certificates with same serial number
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 84% similar
IdenTrust: Cross-signed root certificate mis-issuance
#1965459 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-05-09 · Closed 2025-10-31 · 82% similar
Telia: S/MIME Misissuance incorrect AIA id-ca-caIssuer http:URI
#1672409 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2020-10-21 · Closed 2023-02-22 · 81% similar
Camerfirma: suspicious certificate for com.com

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action