Thanks, Rob, for the investigation. We detected that the certificates were 
incorrectly issued in 2009 with a double serial number. The CA software used in 
recent years had special protection against abusive issuing and revocation of 
certificates with the same serial number. This led to the situation that the 
certificate could not yet be officially revoked in our CRL by normal 
operational procedure. We have already discussed the right options with the 
operators of the root stores. We will continue to try to circumvent the 
protection of our CRLs for these certificates and to allow the use of same 
serial number in our CRL despite different certificates (as an exception).

We will inform in this thread about our next steps.
Reinhard Dietrich
SwissSign
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to