SwissSign: invalid State field in Liechtenstein TLS OV certificates; delayed revocation tracked separately
SwissSign is reporting a certificate issuance incident involving TLS OV certificates for subscribers in Liechtenstein that contained an incorrect StateOrProvinceName value. The bug was opened by SwissSign after a third party reported the issue, and SwissSign then documented the incident in a formal report. SwissSign said the problem affected 18 certificates across 4 subscribers, with 9 still valid when the issue was identified. The company stated that issuance for the related customer MPKI was suspended, the issuance logic was corrected, issuance later resumed after validation, and all affected certificates were revoked or expired naturally. In follow-up discussion, SwissSign first said it had started the revocation timer when it confirmed the misissuance, but later acknowledged that this was an error and that the Certificate Problem Report had been received on 2026-07-22 18:05 UTC. SwissSign then said revocation exceeded the required five-day period by about 12 hours and 30 minutes and that it would open a separate Bugzilla report covering the delayed revocation aspect. The current bug remains assigned to SwissSign and is still open.
- A placeholder subdivision value was created for Liechtenstein.
- A software change altered the source data used to populate the State field, causing non-compliant issuance to begin.
- A third party reported the invalid StateOrProvinceName values in Liechtenstein certificates.
- SwissSign confirmed the issue, suspended issuance for the affected customer MPKI, and corrected the issuance logic.
- Issuance resumed after validation of the fix.
- SwissSign said all affected certificates were revoked or expired naturally.
- SwissSign AG — SwissSign filed a preliminary incident report describing the third-party report, the affected Liechtenstein certificates, and that mis-issuance handling had begun.
- SwissSign AG — SwissSign posted a formal incident report with the affected-certificate count, revocation status, timeline, root cause, and related policy references.
- SwissSign AG — SwissSign added an attachment containing the affected certificates list.
- SwissSign AG — SwissSign posted a scheduled update saying there was no update that week.
- Community commenter — A commenter asked SwissSign to clarify the revocation clock and suggested the case might instead be delayed revocation.
- SwissSign AG — SwissSign said it had started the revocation timer at confirmation time, would update the report, and would open a separate delayed-revocation bug.
- Google representative — Chrome Root Program disagreed with SwissSign's revocation interpretation and cited BR 4.9.5 and the five-day deadline from CPR receipt.
- SwissSign AG — SwissSign acknowledged error in its earlier interpretation, confirmed the CPR receipt time and revocation completion time, and said revocation exceeded five days by about 12 hours and 30 minutes.
- SwissSign AG — SwissSign posted a scheduled update saying there was no update that week.
- SwissSign AG — SwissSign posted a scheduled update saying there was no update that week.
- SwissSign AG — SwissSign posted a scheduled update saying there was no update today.