Telia: S/MIME Misissuance - incorrect subject information for Multipurpose sponsor-validated-profile
Telia Company identified a misissuance of S/MIME Multipurpose certificates during a self-audit on January 23, 2026. The misissued certificates contained incorrect subject information that did not belong to a natural person, violating S/MIME BR and Telia CA policies. Upon discovery, Telia revoked the affected certificates and informed the subscribers to renew them with the correct profile. A full incident report was submitted detailing the root causes and preventive measures taken, including revisions to self-audit practices and changes to the certificate issuance process to prevent future occurrences. The case has been resolved with all action items completed.
- Misissued S/MIME Multipurpose certificate found during self-audit.
- Full incident report submitted detailing misissuance and corrective actions.
- Final call for comments on the incident report before closure.
- Teliacompany representative — Preliminary incident report submitted regarding misissued S/MIME certificates.
- Teliacompany representative — Update on findings and revocation of affected certificates.
- Teliacompany representative — Full incident report detailing root causes and remediation actions submitted.
- Teliacompany representative — Closure report summary provided, detailing completed action items.
- CCADB representative — Final call for comments on the incident report.