eMudhra emSign PKI Services: ACME workflow added unrequested “www” SAN without subscriber authorization
This case concerns eMudhra’s ACME issuance workflow automatically adding the corresponding “www” subdomain to certificates requested for a base domain only. eMudhra said the behavior occurred without explicit subscriber authorization and was inconsistent with CA/B Forum Baseline Requirements for including domain names in certificates. The company stated that the issue was identified after a customer inquiry, affected 239 TLS/SSL DV and OV end-entity certificates, and that all 239 valid affected certificates were revoked by 2026-06-02 19:15 UTC. eMudhra also said the unconditional ACME auto-addition logic was disabled on 2026-05-30, and that the same “www” option remains available in other channels only through explicit subscriber opt-in. In response to Mozilla’s question, eMudhra clarified that DNS TXT record-based domain validation was used and that the incident was limited to subscriber authorization, not domain validation. The latest status update says all listed remediation items are complete, including the post-issuance monitoring item, and the bug remains open with no closure noted in the thread.
- Earliest affected ACME-issued subscriber certificate was issued with an unrequested “www” SAN added to a base-domain request.
- eMudhra disabled the ACME www auto-addition logic.
- All 239 valid affected certificates were revoked.
- eMudhra marked the remaining remediation and monitoring action items complete.
- Emudhra representative — Filed a preliminary incident report describing the ACME workflow’s automatic inclusion of “www” in the SAN for base-domain requests.
- Emudhra representative — Submitted the full incident report stating the issue affected 239 certificates and that all valid affected certificates were revoked by 2026-06-02 19:15 UTC.
- Mozilla representative — Asked eMudhra to clarify which ACME validation method was used and whether the automatically-added “www” identifier was separately validated before issuance.
- Emudhra representative — Confirmed DNS TXT record-based validation was used, domain control was properly established, and the incident was limited to subscriber authorization.
- Emudhra representative — Reported that the pre-issuance SAN vs CSR validation gate was complete, while the non-ACME channel audit and post-issuance monitoring were still in progress.
- Emudhra representative — Posted a status update marking the non-ACME channel audit complete and leaving automated post-issuance monitoring ongoing.
- Emudhra representative — Requested that the Next Update field be set to 2026-08-31.
- Emudhra representative — Posted a status update marking the post-issuance monitoring action item complete.