← eMudhra Technologies Limited cases
Bugzilla #2043837 Ca Certificate Compliance Certificate Misissuance Validation Issue Revocation Issue Problem Reporting Failure

eMudhra emSign PKI Services: ACME workflow added unrequested “www” SAN without subscriber authorization

ASSIGNED eMudhra Technologies Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns eMudhra’s ACME issuance workflow automatically adding the corresponding “www” subdomain to the SAN of certificates requested for a base domain only. eMudhra said the behavior occurred without explicit subscriber authorization and was inconsistent with CA/B Forum Baseline Requirements Section 4.2.1. The company stated that the issue was identified after a customer inquiry, affected 239 TLS/SSL DV and OV end-entity certificates, and that all 239 valid affected certificates were revoked by 2026-06-02 19:15 UTC. eMudhra also said the unconditional ACME auto-addition logic was disabled on 2026-05-30, and that the same “www” option remains available in other channels only through explicit subscriber opt-in. In response to Mozilla’s question, eMudhra clarified that DNS TXT record-based domain validation was used and that the incident was limited to subscriber authorization, not domain validation. The latest thread update says the non-ACME channel audit is complete, while automated post-issuance monitoring remains ongoing and the next update was requested for 2026-08-31.

Model: gpt-5.4-mini Generated: 2026-06-13 21:33 UTC Revised: 2026-07-26 06:01 UTC Confidence: 0.96 11 comments
Chronology
  1. Earliest affected ACME-issued subscriber certificate was issued with an unrequested “www” SAN added to a base-domain request.
  2. eMudhra disabled the ACME www auto-addition logic.
  3. All 239 valid affected certificates were revoked.
  4. eMudhra reported the non-ACME channel audit complete, with post-issuance monitoring still ongoing.
Thread Activity
  1. Emudhra representative — Filed a preliminary incident report describing the ACME workflow’s automatic inclusion of “www” in the SAN for base-domain requests.
  2. Emudhra representative — Submitted the full incident report stating the issue affected 239 certificates and that all valid affected certificates were revoked by 2026-06-02 19:15 UTC.
  3. Mozilla representative — Asked eMudhra to clarify which ACME validation method was used and whether the automatically-added “www” identifier was separately validated before issuance.
  4. Emudhra representative — Confirmed DNS TXT record-based validation was used, domain control was properly established, and the incident was limited to subscriber authorization.
  5. Emudhra representative — Reported that the pre-issuance SAN vs CSR validation gate was complete, while the non-ACME channel audit and post-issuance monitoring were still in progress.
  6. Emudhra representative — Posted a status update marking the non-ACME channel audit complete and leaving automated post-issuance monitoring ongoing.
  7. Emudhra representative — Requested that the Next Update field be set to 2026-08-31.
Participants
Emudhra representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1866091 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-11-22 · Closed 2023-12-11 · 78% similar
SwissSign: EV JurisdictionStateOrProvinceName - one certificate not selected for revocation
#2023458 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-03-15 · Closed 2026-06-12 · 78% similar
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
#1735247 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-11 · Closed 2023-02-22 · 77% similar
Let's Encrypt: Mis-issued certificates related to SC48v2
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 77% similar
QuoVadis: Incorrect keyUsage for ECC certificate
#1782391 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-07-31 · Closed 2023-02-22 · 77% similar
GlobalSign: EV certificate with wildcard domain in common name and SAN
#1639032 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-05-18 · Closed 2023-02-22 · 77% similar
DigiCert: "Internet Widgits Pty Ltd" in organizationalUnitName
#1851164 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-09-01 · Closed 2023-09-22 · 77% similar
SwissSign: S/MIME wrong key Usage
#1590810 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-23 · Closed 2023-02-22 · 77% similar
Sectigo: EV SSL Certificates with incorrect businessCategory

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action