← PostSignum cases
Bugzilla #2016722 Certificate Misissuance

PostSignum: Mis-issued certificate

RESOLVED FIXED PostSignum
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

PostSignum reported a mis-issuance incident involving a TLS certificate issued with unverified data due to a human error during a service intervention. The CA operator mistakenly selected the operational certificate policy instead of the test policy while issuing a test certificate. The mis-issued certificate was identified and revoked within minutes of issuance. PostSignum has since implemented new internal procedures and training for CA operators to prevent similar incidents in the future, including a requirement for dual operator verification for certificate issuance from the CA core. The incident report has been completed and is now closed.

Model: gpt-4o-mini Generated: 2026-06-13 21:08 UTC Revised: 2026-06-16 18:35 UTC Confidence: 0.90 16 comments
Chronology
  1. Mis-issued certificate identified and revoked
Thread Activity
  1. Cpost representative — Preliminary Incident Report Summary submitted.
  2. Cpost representative — Full Incident Report detailing the mis-issuance and corrective actions taken.
  3. Cpost representative — Report Closure Summary provided, confirming completion of remediation actions.
  4. CCADB representative — Final call for comments on the Incident Report before closure.
Participants
Cpost representative HARICA Sectigo Mm representative CCADB representative
Similar Local Cases
#1895006 RESOLVED Certificate Misissuance Opened 2024-05-03 · Closed 2024-08-23 · 86% similar
IdenTrust: unintended creation of a Root CA certificate
#1959721 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-04-10 · Closed 2025-06-12 · 78% similar
Lawtrust: The S/MIME CA’s policy identifiers did not align with the CA/Browser Forum Requirements.
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 78% similar
Financijska agencija (Fina): Mis-issued certificates
#2007132 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-12-19 · Closed 2026-02-11 · 77% similar
Disig: Certificates with invalid embedded SCT signature
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 76% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#1883711 RESOLVED Certificate Misissuance Opened 2024-03-05 · Closed 2024-07-09 · 76% similar
e-commerce monitoring gmbh: precertificate validity does not match leaf certificate
#1889672 RESOLVED Certificate Misissuance Opened 2024-04-04 · Closed 2024-06-01 · 76% similar
Disig: Certificates with incorrect Subject attribute order
#1951415 RESOLVED Certificate Misissuance Delayed Revocation Opened 2025-03-03 · Closed 2025-05-08 · 75% similar
Chunghwa Telecom: Failure to check restrictive CAA record during Migration

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action