Microsec self-reported incident: DV test website certificate issued under incorrect root during migration
Microsec self-reported an incident involving its DV test website certificate issuance during a migration of ECC-based certificate issuance. Microsec said that during the June 2025 migration, the test website https://eosslca2017-dv-valid.e-szigno.hu was transferred from the “e-Szigno Root CA 2017” multifunctional root to the “e-Szigno TLS Root CA 2023” dedicated root along with user certificates. Microsec stated that after the change the test site worked, but the targeted root could not be tested, so the DV testing option under “e-Szigno Root CA 2017” was unavailable while the bug existed. Microsec reported that the error did not affect certificates issued to customers or the operation of other test sites. In response to detection, Microsec stopped the automatic issuance of test website certificates and the migration of RSA-based certificate issuance, and said the test website error was fixed within two days of detection. Microsec also reported remediation by creating dedicated CRM services for managing test website certificates separately from live customer certificate services, and requested closure of the incident report; the bug is marked RESOLVED with resolution FIXED.
- Microsec’s ECC-based certificate issuance migration began, during which the DV test website certificate was transferred to a different root.
- Microsec identified the non-compliance affecting the DV test website certificate issuance.
- Microsec ended the non-compliance period and fixed the test website error after detection.
- Microsec submitted a report closure summary and requested closure of the incident report.
- Microsec representative — Microsec posted a preliminary incident report describing the DV test website certificate being transferred to an incorrect root during migration and noting the issue was fixed within two days of detection.
- Microsec representative — Microsec stated that test websites were working fine and that it was working on the full incident report.
- Microsec representative — Microsec posted a full incident report including timeline dates, impact (63 certificates issued during the error period), and remediation/analysis, and identified the incident as self-reported.
- Microsec representative — Microsec posted a report closure summary with root cause, remediation (dedicated CRM services for test websites), and commitment that action items were completed, requesting closure.
- CCADB representative — CCADB incident reporting issued a final call for comments before closure on approximately 2026-02-26.