PostSignum: Mis-issued certificate
PostSignum reported a mis-issuance incident involving a TLS certificate issued with unverified data due to a human error during a service intervention. The CA operator mistakenly selected the operational certificate policy instead of the test policy while issuing a test certificate. The mis-issued certificate was identified and revoked within minutes of issuance. PostSignum has since implemented new internal procedures and training for CA operators to prevent similar incidents in the future, including a requirement for dual operator verification for certificate issuance from the CA core. The incident report has been completed and is now closed.
- Mis-issued certificate identified and revoked
- Cpost representative — Preliminary Incident Report Summary submitted.
- Cpost representative — Full Incident Report detailing the mis-issuance and corrective actions taken.
- Cpost representative — Report Closure Summary provided, confirming completion of remediation actions.
- CCADB representative — Final call for comments on the Incident Report before closure.