← SwissSign AG cases
Bugzilla #2057448 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Delayed Revocation

SwissSign: invalid State field in Liechtenstein TLS OV certificates; delayed revocation tracked separately

ASSIGNED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SwissSign is reporting a certificate issuance incident involving TLS OV certificates for subscribers in Liechtenstein that contained an incorrect StateOrProvinceName value. The bug was opened by SwissSign after a third party reported the issue, and SwissSign then documented the incident in a formal report. SwissSign said the problem affected 18 certificates across 4 subscribers, with 9 still valid when the issue was identified. The company stated that issuance for the related customer MPKI was suspended, the issuance logic was corrected, issuance later resumed after validation, and all affected certificates were revoked or expired naturally. In follow-up discussion, SwissSign first said it had started the revocation timer when it confirmed the misissuance, but later acknowledged that this was an error and that the Certificate Problem Report had been received on 2026-07-22 18:05 UTC. SwissSign then said revocation exceeded the required five-day period by about 12 hours and 30 minutes and that it would open a separate Bugzilla report covering the delayed revocation aspect. The current bug remains assigned to SwissSign and is still open.

Model: gpt-5.4-mini Generated: 2026-07-26 06:26 UTC Revised: 2026-09-06 06:02 UTC Confidence: 0.98 11 comments
Chronology
  1. A placeholder subdivision value was created for Liechtenstein.
  2. A software change altered the source data used to populate the State field, causing non-compliant issuance to begin.
  3. A third party reported the invalid StateOrProvinceName values in Liechtenstein certificates.
  4. SwissSign confirmed the issue, suspended issuance for the affected customer MPKI, and corrected the issuance logic.
  5. Issuance resumed after validation of the fix.
  6. SwissSign said all affected certificates were revoked or expired naturally.
Thread Activity
  1. SwissSign AG — SwissSign filed a preliminary incident report describing the third-party report, the affected Liechtenstein certificates, and that mis-issuance handling had begun.
  2. SwissSign AG — SwissSign posted a formal incident report with the affected-certificate count, revocation status, timeline, root cause, and related policy references.
  3. SwissSign AG — SwissSign added an attachment containing the affected certificates list.
  4. SwissSign AG — SwissSign posted a scheduled update saying there was no update that week.
  5. Community commenter — A commenter asked SwissSign to clarify the revocation clock and suggested the case might instead be delayed revocation.
  6. SwissSign AG — SwissSign said it had started the revocation timer at confirmation time, would update the report, and would open a separate delayed-revocation bug.
  7. Google representative — Chrome Root Program disagreed with SwissSign's revocation interpretation and cited BR 4.9.5 and the five-day deadline from CPR receipt.
  8. SwissSign AG — SwissSign acknowledged error in its earlier interpretation, confirmed the CPR receipt time and revocation completion time, and said revocation exceeded five days by about 12 hours and 30 minutes.
  9. SwissSign AG — SwissSign posted a scheduled update saying there was no update that week.
  10. SwissSign AG — SwissSign posted a scheduled update saying there was no update that week.
  11. SwissSign AG — SwissSign posted a scheduled update saying there was no update today.
Participants
SwissSign AG Community commenter Google representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2033000 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-04-17 · Closed 2026-07-09 · 88% similar
SwissSign: Certificate Profile error for S/MIME MV
#2058918 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-29 Still Open · 82% similar
CFCA: Incorrect countryName values in OV subscriber certificates
#1990282 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-11 · 82% similar
SwissSign: recommendation on linting software updates
#1428877 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-01-08 · Closed 2023-02-22 · 81% similar
SwissSign: Invalid DNSName in SAN
#1443731 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-03-07 · Closed 2023-02-22 · 81% similar
SwissSign: Cert issued with a to long validity period
#1860750 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-10-24 · Closed 2023-11-08 · 81% similar
SwissSign: EV code in JurisdiktionStateOrProvinceName
#2061746 ASSIGNED Self Reported Incident Certificate Misissuance Delayed Revocation Revocation Issue Opened 2026-08-07 Still Open · 80% similar
ACCV: Issuance of Server TLS Certificates with CP/CPS Discrepancies
#1473971 RESOLVED Self Reported Incident Certificate Misissuance Opened 2018-07-06 · Closed 2023-02-22 · 80% similar
SwissSign: Domain validated certificate but with stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action