← eMudhra Technologies Limited cases
Bugzilla #2043837 Certificate Misissuance

eMudhra emSign PKI Services : www Subdomain Inclusion in Certificate SAN via ACME Issuance Workflow

ASSIGNED eMudhra Technologies Limited
AI Summary

eMudhra Technologies Limited identified a misissuance incident where the ACME issuance workflow automatically included the www subdomain in the Subject Alternative Name (SAN) extension for certificates requested for base domains only. This behavior occurred without explicit subscriber authorization and was found to violate CA/Browser Forum Baseline Requirements. Following a customer inquiry, eMudhra revoked all 239 affected certificates and corrected the issue in their issuance pipeline. The incident was reported and a full analysis was conducted to ensure compliance moving forward.

Model: gpt-4o-mini Generated: 2026-06-13 21:33 UTC Confidence: 0.90
Chronology
  1. Earliest affected subscriber certificate issued via ACME pipeline.
  2. Customer complaint triaged; internal investigation initiated.
  3. ACME www auto-addition logic was corrected.
  4. Revocation of all 239 valid affected certificates completed.
  5. Full Incident Report prepared and submitted.
Participants
Naveen Kumar ML
Similar Local Cases
#1665688 RESOLVED Certificate Misissuance Opened 2020-09-17 · Closed 2023-02-22 · 53% similar
eMudhra: emSign CA ECC Test Certificate Misissuance
#1763700 RESOLVED Certificate Misissuance Opened 2022-04-07 · Closed 2023-02-22 · 51% similar
eMudhra: emSign CA Invalid AIA Extension Value
#1745015 RESOLVED Certificate Misissuance Opened 2021-12-08 · Closed 2023-02-22 · 50% similar
eMudhra: emSign CA Invalid OrganizationalUnitName
#1922906 RESOLVED Certificate Misissuance Opened 2024-10-05 · Closed 2025-02-12 · 43% similar
FNMT: LDAP URI in CRL Distribution Points Extension
#1048045 RESOLVED Certificate Misissuance Opened 2014-08-03 · Closed 2022-11-14 · 43% similar
GlobalSign Partner: No SAN
#1462423 RESOLVED Certificate Misissuance Opened 2018-05-17 · Closed 2023-02-22 · 42% similar
NetLock: CN not in SAN
#1785865 RESOLVED Certificate Misissuance Opened 2022-08-18 · Closed 2024-05-09 · 42% similar
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension
#1696872 RESOLVED Certificate Misissuance Opened 2021-03-08 · Closed 2025-03-20 · 42% similar
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action