eMudhra self-reported issuance of TLS test website certificates with unauthorized clientAuth EKU
eMudhra reported that four TLS leaf certificates were issued on 2026-08-25 for its own internal test websites. The certificates asserted both serverAuth and clientAuth Extended Key Usages, while the emSign TLS CP/CPS restricts subscriber certificates to serverAuth only. eMudhra said the issue was detected internally during monitoring on 2026-08-26 and opened the bug as a preliminary incident report. The thread does not describe any external subscriber impact or revocation action. On 2026-09-03, eMudhra said it was continuing internal analysis and would publish the Full Incident Report within the expected timeline.
- Four TLS leaf certificates were issued for emSign internal test websites with both serverAuth and clientAuth EKUs.
- eMudhra internally detected the EKU deviation during certificate monitoring and disclosed the incident.
- eMudhra said it was continuing internal analysis and would publish the Full Incident Report within the expected timeline.
- Emudhra representative — Naveen Kumar ML filed a preliminary incident report stating that four TLS leaf certificates for internal test websites included clientAuth in violation of the published CP/CPS.
- Emudhra representative — He said internal analysis was continuing and that the Full Incident Report would be published within the expected timeline.