← Microsec Ltd. cases
Bugzilla #2013576 Self Reported Incident Certificate Misissuance

Microsec self-reported incident: DV test website certificate issued under incorrect root during migration

RESOLVED FIXED Microsec Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsec self-reported an incident involving its DV test website certificate issuance during a migration of ECC-based certificate issuance. Microsec said that during the June 2025 migration, the test website https://eosslca2017-dv-valid.e-szigno.hu was transferred from the “e-Szigno Root CA 2017” multifunctional root to the “e-Szigno TLS Root CA 2023” dedicated root along with user certificates. Microsec stated that after the change the test site worked, but the targeted root could not be tested, so the DV testing option under “e-Szigno Root CA 2017” was unavailable while the bug existed. Microsec reported that the error did not affect certificates issued to customers or the operation of other test sites. In response to detection, Microsec stopped the automatic issuance of test website certificates and the migration of RSA-based certificate issuance, and said the test website error was fixed within two days of detection. Microsec also reported remediation by creating dedicated CRM services for managing test website certificates separately from live customer certificate services, and requested closure of the incident report; the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:16 UTC Revised: 2026-06-16 19:19 UTC Confidence: 0.90 6 comments
Chronology
  1. Microsec’s ECC-based certificate issuance migration began, during which the DV test website certificate was transferred to a different root.
  2. Microsec identified the non-compliance affecting the DV test website certificate issuance.
  3. Microsec ended the non-compliance period and fixed the test website error after detection.
  4. Microsec submitted a report closure summary and requested closure of the incident report.
Thread Activity
  1. Microsec representative — Microsec posted a preliminary incident report describing the DV test website certificate being transferred to an incorrect root during migration and noting the issue was fixed within two days of detection.
  2. Microsec representative — Microsec stated that test websites were working fine and that it was working on the full incident report.
  3. Microsec representative — Microsec posted a full incident report including timeline dates, impact (63 certificates issued during the error period), and remediation/analysis, and identified the incident as self-reported.
  4. Microsec representative — Microsec posted a report closure summary with root cause, remediation (dedicated CRM services for test websites), and commitment that action items were completed, requesting closure.
  5. CCADB representative — CCADB incident reporting issued a final call for comments before closure on approximately 2026-02-26.
Participants
Microsec representative Community commenter CCADB representative
Similar Local Cases
#2005939 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-12-14 · Closed 2026-03-13 · 100% similar
Microsec: CT Logging mistakes
#1622539 RESOLVED Self Reported Incident Opened 2020-03-14 · Closed 2023-02-22 · 87% similar
Microsec: Issuance of 2 IVCP precertificates without givenName, surName, localityName fields
#1925239 RESOLVED Self Reported Incident Opened 2024-10-17 · Closed 2025-01-14 · 87% similar
Microsec: Expired Certificates on test Pages for Revocation
#1865880 RESOLVED Self Reported Incident Opened 2023-11-21 · Closed 2024-02-14 · 86% similar
Microsec: Findings in 2023 Audit
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 79% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 78% similar
IdenTrust: Cross-signed root certificate mis-issuance
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 78% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)
#1889699 RESOLVED Certificate Misissuance Incident Revocation Issue Opened 2024-04-04 · Closed 2024-08-28 · 78% similar
Microsec: Disallowed subject attribute field in DV certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action