← Government of Korea, KLID cases
Bugzilla #2032478 Certificate Misissuance

Government of Korea: Misissuance detected by PKIMetal

CLOSED Government of Korea, KLID
AI Summary

The Government of Korea investigated certificate profile issues related to misissued OV TLS Subscriber Certificates under the legacy GPKIRootCA1 hierarchy. The investigation revealed that certain certificates contained non-compliant profile values, including prohibited key usage and improper CRL distribution points. Following the identification of these issues, the Government initiated revocation actions, ultimately revoking all affected certificates. The incident highlighted the need for improved internal controls and automated linting processes to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:10 UTC Confidence: 0.90
Chronology
  1. Bugzilla Bug 2032478 was opened, reporting certificate profile issues.
  2. Government of Korea's engineering team became aware of the shared profile issue.
  3. Government of Korea revoked the initially identified certificates.
  4. Government of Korea revoked additional certificates.
  5. Final certificate with relevant non-compliant profile values was revoked.
  6. All remaining valid affected certificates were confirmed revoked.
Participants
Ji Eun Seong incident-reporting@ccadb.org
External References
Similar Local Cases
#2009941 RESOLVED Certificate Misissuance Opened 2026-01-13 · Closed 2026-04-06 · 51% similar
Firmaprofesional: Misissuance of TLS Subordinate CA "AC Firmaprofesional - Secure Web 2024"
#2012157 RESOLVED Certificate Misissuance Opened 2026-01-23 · Closed 2026-03-08 · 49% similar
Actalis: Issuance of certificate using keys previously reported as compromised
#2032482 ASSIGNED Certificate Misissuance Opened 2026-04-16 Still Open · 49% similar
OATI: Misissuance detected by PKIMetal
#2032473 ASSIGNED Certificate Misissuance Opened 2026-04-16 Still Open · 49% similar
CCA India: Misissuance detected by PKIMetal
#2032468 ASSIGNED Certificate Misissuance Opened 2026-04-16 Still Open · 48% similar
VISA: Misissuance detected by PKIMetal
#2032479 RESOLVED Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-13 · 48% similar
Certisign: Misissuance detected by PKIMetal
#1981680 RESOLVED Certificate Misissuance Opened 2025-08-07 · Closed 2025-09-26 · 48% similar
TunTrust: SSL OV mis-issuance against CP/CPS (Email attribute)
#2032476 RESOLVED Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-07 · 46% similar
Microsoft PKI Services: Misissuance detected by PKIMetal

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action