eMudhra emSign PKI Services: ACME workflow added unrequested “www” SAN without subscriber authorization
This case concerns eMudhra’s ACME issuance workflow automatically adding the corresponding “www” subdomain to the SAN of certificates requested for a base domain only. eMudhra said the behavior occurred without explicit subscriber authorization and was inconsistent with CA/B Forum Baseline Requirements Section 4.2.1. The company stated that the issue was identified after a customer inquiry, affected 239 TLS/SSL DV and OV end-entity certificates, and that all 239 valid affected certificates were revoked by 2026-06-02 19:15 UTC. eMudhra also said the unconditional ACME auto-addition logic was disabled on 2026-05-30, and that the same “www” option remains available in other channels only through explicit subscriber opt-in. In response to Mozilla’s question, eMudhra clarified that DNS TXT record-based domain validation was used and that the incident was limited to subscriber authorization, not domain validation. The latest thread update says the non-ACME channel audit is complete, while automated post-issuance monitoring remains ongoing and the next update was requested for 2026-08-31.
- Earliest affected ACME-issued subscriber certificate was issued with an unrequested “www” SAN added to a base-domain request.
- eMudhra disabled the ACME www auto-addition logic.
- All 239 valid affected certificates were revoked.
- eMudhra reported the non-ACME channel audit complete, with post-issuance monitoring still ongoing.
- Emudhra representative — Filed a preliminary incident report describing the ACME workflow’s automatic inclusion of “www” in the SAN for base-domain requests.
- Emudhra representative — Submitted the full incident report stating the issue affected 239 certificates and that all valid affected certificates were revoked by 2026-06-02 19:15 UTC.
- Mozilla representative — Asked eMudhra to clarify which ACME validation method was used and whether the automatically-added “www” identifier was separately validated before issuance.
- Emudhra representative — Confirmed DNS TXT record-based validation was used, domain control was properly established, and the incident was limited to subscriber authorization.
- Emudhra representative — Reported that the pre-issuance SAN vs CSR validation gate was complete, while the non-ACME channel audit and post-issuance monitoring were still in progress.
- Emudhra representative — Posted a status update marking the non-ACME channel audit complete and leaving automated post-issuance monitoring ongoing.
- Emudhra representative — Requested that the Next Update field be set to 2026-08-31.