← SwissSign AG cases
Bugzilla #2065061 Ca Certificate Compliance Incident Self Reported Incident Remediation Tracking

SwissSign preliminary incident report on stateOrProvinceName formatting

ASSIGNED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SwissSign opened this bug as a preliminary incident report after a third party asked about unexpected stateOrProvinceName attribute formatting in OV and EV certificates. SwissSign said its certificates use state shortcodes without the ISO 3166-1 country-code prefix, and it started an investigation. In its conclusion, SwissSign stated that using either the state name or the shortcode is compliant with the relevant TLS Baseline Requirements, EV Guidelines, and SwissSign CP/CPS. CCADB Support asked whether the bug should be closed as INVALID, and SwissSign agreed that it could be closed as INVALID if there were no further questions. CCADB then issued a final call for comments and said the bug would be closed as INVALID on or about 2026-09-01 if no further discussion occurred.

Model: gpt-5.4-mini Generated: 2026-08-26 10:55 UTC Confidence: 0.93 6 comments
Chronology
  1. SwissSign opened a preliminary incident report about OV and EV certificates using state shortcodes without the ISO country-code prefix.
  2. SwissSign concluded that the formatting was compliant with the TLS BR, EV Guidelines, and SwissSign CP/CPS.
  3. CCADB issued a final call for comments and said the bug would be closed as INVALID if no further questions were raised.
Thread Activity
  1. SwissSign AG — Roman Fischer reported the issue as a third-party inquiry about unexpected certificate attribute combinations and said SwissSign had started an investigation.
  2. SwissSign AG — Roman Fischer explained SwissSign's lookup-table approach and concluded the use of the state shortcode without the country-code prefix was compliant.
  3. CCADB representative — CCADB Support said it would continue monitoring the bug and consider additional information when deciding next action.
  4. CCADB representative — CCADB Support asked whether the bug should be closed as INVALID.
  5. SwissSign AG — Roman Fischer agreed the bug could be closed as INVALID if there were no questions or discussion.
  6. CCADB representative — CCADB Support gave a final call for comments and said the bug would be closed as INVALID on approximately 2026-09-01.
Participants
SwissSign AG CCADB representative
Similar Local Cases
#2033000 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-04-17 · Closed 2026-07-09 · 97% similar
SwissSign: Certificate Profile error for S/MIME MV
#1860750 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-10-24 · Closed 2023-11-08 · 87% similar
SwissSign: EV code in JurisdiktionStateOrProvinceName
#1965828 RESOLVED Self Reported Incident Security Incident Opened 2025-05-12 · Closed 2025-08-19 · 84% similar
SwissSign: OCSP outage
#1995252 RESOLVED Incident Opened 2025-10-20 · Closed 2025-12-11 · 84% similar
SwissSign: Attribute Change process did not revoke single-domain certificates
#1990282 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-11 · 82% similar
SwissSign: recommendation on linting software updates
#2056223 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-20 · Closed 2026-08-08 · 81% similar
D-Trust OCSP Responder Certificates Include CA/B Forum DV Policy OID
#2048444 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-06-18 · Closed 2026-08-04 · 79% similar
IdenTrust: End Entity TLS certificate mis-issuance against CP/CPS (IdenTrust certificate policy OIDs)
#1950574 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2025-02-26 · Closed 2025-09-15 · 79% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action