← eMudhra Technologies Limited cases
Bugzilla #2066864 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened By Ca

eMudhra self-reported issuance of TLS test website certificates with unauthorized clientAuth EKU

ASSIGNED eMudhra Technologies Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

eMudhra reported that four TLS leaf certificates were issued on 2026-08-25 for its own internal test websites. The certificates asserted both serverAuth and clientAuth Extended Key Usages, while the emSign TLS CP/CPS restricts subscriber certificates to serverAuth only. eMudhra said the issue was detected internally during monitoring on 2026-08-26 and opened the bug as a preliminary incident report. The thread does not describe any external subscriber impact or revocation action. On 2026-09-03, eMudhra said it was continuing internal analysis and would publish the Full Incident Report within the expected timeline.

Model: gpt-5.4-mini Generated: 2026-09-06 10:58 UTC Confidence: 0.98 2 comments
Chronology
  1. Four TLS leaf certificates were issued for emSign internal test websites with both serverAuth and clientAuth EKUs.
  2. eMudhra internally detected the EKU deviation during certificate monitoring and disclosed the incident.
  3. eMudhra said it was continuing internal analysis and would publish the Full Incident Report within the expected timeline.
Thread Activity
  1. Emudhra representative — Naveen Kumar ML filed a preliminary incident report stating that four TLS leaf certificates for internal test websites included clientAuth in violation of the published CP/CPS.
  2. Emudhra representative — He said internal analysis was continuing and that the Full Incident Report would be published within the expected timeline.
Participants
Emudhra representative
External References
Similar Local Cases
#2057520 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2026-07-24 Still Open · 87% similar
eMudhra emSign PKI Services: Invalid Subject Locality/State Values
#1999241 RESOLVED Incident Repository Issue Opened 2025-11-10 · Closed 2025-12-24 · 77% similar
eMudhra emSign PKI Services : Delayed Publication of Issuing CA Certificates in CCADB
#2067210 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-08-27 Still Open · 71% similar
Actalis: Incorrect CRL Distribution Point in TLS Server Certificates
#2065616 ASSIGNED Ca Certificate Compliance Self Reported Incident Incident Audit Finding Opened 2026-08-21 Still Open · 71% similar
IdenTrust: Expired certificates for "Revoked" test websites
#1627346 RESOLVED Ca Certificate Compliance Self Reported Incident Certificate Misissuance Delayed Revocation Opened 2020-04-03 · Closed 2023-02-22 · 71% similar
Entrust: S/MIME Certificate Issued with Incorrect Policy OID
#1802916 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-11-28 · Closed 2023-04-24 · 71% similar
Entrust: EV TLS Certificate incorrect jurisdiction
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 71% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1983955 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-08-19 · Closed 2025-09-15 · 70% similar
Certigna: Subscriber certificate with EKU clientAuth only

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action