← eMudhra Technologies Limited cases
Bugzilla #2043837
Certificate Misissuance
eMudhra emSign PKI Services : www Subdomain Inclusion in Certificate SAN via ACME Issuance Workflow
ASSIGNED
eMudhra Technologies Limited
AI Summary
eMudhra Technologies Limited identified a misissuance incident where the ACME issuance workflow automatically included the www subdomain in the Subject Alternative Name (SAN) extension for certificates requested for base domains only. This behavior occurred without explicit subscriber authorization and was found to violate CA/Browser Forum Baseline Requirements. Following a customer inquiry, eMudhra revoked all 239 affected certificates and corrected the issue in their issuance pipeline. The incident was reported and a full analysis was conducted to ensure compliance moving forward.
Chronology
- Earliest affected subscriber certificate issued via ACME pipeline.
- Customer complaint triaged; internal investigation initiated.
- ACME www auto-addition logic was corrected.
- Revocation of all 239 valid affected certificates completed.
- Full Incident Report prepared and submitted.
Participants
Naveen Kumar ML
External References
Similar Local Cases
eMudhra: emSign CA ECC Test Certificate Misissuance
eMudhra: emSign CA Invalid AIA Extension Value
eMudhra: emSign CA Invalid OrganizationalUnitName
FNMT: LDAP URI in CRL Distribution Points Extension
GlobalSign Partner: No SAN
NetLock: CN not in SAN
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID