← Government of Korea, KLID cases
Bugzilla #2032478 Self Reported Incident Certificate Misissuance

Government of Korea: Misissuance detected by PKIMetal

ASSIGNED Government of Korea, KLID
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The Government of Korea, KLID, acknowledged a misissuance incident involving certain OV TLS Subscriber Certificates issued under the legacy GPKIRootCA1 hierarchy. The issues were identified by PKIMetal and included prohibited key usage and improper CRL distribution points. Following the report, KLID initiated an incident investigation, revoked the affected certificates, and conducted a comprehensive review of all valid certificates. As of June 5, 2026, all identified non-compliant certificates have been revoked, and KLID has committed to strengthening its internal controls to prevent future occurrences. A full incident report was published detailing the timeline and actions taken.

Model: gpt-4o-mini Generated: 2026-06-13 21:10 UTC Revised: 2026-06-16 19:08 UTC Confidence: 0.85 19 comments
Chronology
  1. Bug 2032478 was opened, reporting certificate profile issues.
  2. KLID became technically aware of the shared profile issue.
  3. KLID revoked the initially identified certificates.
  4. KLID confirmed that all affected certificates were revoked.
Thread Activity
  1. CCADB representative — Report of misissuance issues detected by PKIMetal.
  2. Klid representative — KLID acknowledged the issues and initiated an incident investigation.
  3. Klid representative — KLID provided a full incident report summary.
  4. Klid representative — KLID confirmed all affected certificates were revoked.
Participants
CCADB representative Klid representative Ml representative Community commenter
External References
Similar Local Cases
#2007070 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2025-12-19 · Closed 2026-03-30 · 85% similar
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)
#1965459 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-05-09 · Closed 2025-10-31 · 80% similar
Telia: S/MIME Misissuance incorrect AIA id-ca-caIssuer http:URI
#2007132 RESOLVED Certificate Misissuance Self Reported Incident Opened 2025-12-19 · Closed 2026-02-11 · 80% similar
Disig: Certificates with invalid embedded SCT signature
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 80% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised
#1981680 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Linting Quality Issue Opened 2025-08-07 · Closed 2025-09-26 · 80% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 79% similar
IdenTrust: Cross-signed root certificate mis-issuance
#2005939 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-12-14 · Closed 2026-03-13 · 78% similar
Microsec: CT Logging mistakes
#1959721 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-04-10 · Closed 2025-06-12 · 78% similar
Lawtrust: The S/MIME CA’s policy identifiers did not align with the CA/Browser Forum Requirements.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action