This is an incident report for one certificate issued by Buypass on September 
23rd 2019 noncompliant with BR 7.1. The certificate, issued to a Swedish 
organization, has an error in the subject:postalCode field. The postalCode 
value is set to 2153 while the correct value should be 21532.

The error was discovered at 13:30 on September 25th 2019 during internal 

We use several applications to register certificate requests. One of these 
applications, deployed June 2019, formatted the postal code for Swedish 
addresses wrong.  The application retrieves correct address information from 
the Swedish Business Register (SE-21532 MALMÖ), but formats the postal code 
erroneous and stores this as SE-2153 MALMÖ.

Timeline after the certificate was issued:

2019-09-‎23, 08:40: The certificate was issued with the erroneous postal code
2019-09-25, 13:30: The error in the certificate was discovered during internal 
2019-09-26, 08:46: The certificate was revoked in agreement with the Subscriber
2019-09-26, 14:00: A bug in the application was identified, fixed and verified
2019-09-26, 15:00: We checked that no other certificates issued in the relevant 
period had the same error

The bug in the application was fixed immediately so we have stopped issuing 
certificates with this problem.

One (1) cert – issued September 23rd, 2019

The bug was introduced due to a misunderstanding of how to format Swedish 
postal codes.

We do perform manual controls to verify that address information is correctly 
formatted before issuance, but in this case the manual controls did not detect 
the formatting error.

The application is used only for newly introduced type of certificates and the 
formatting error was only occurring for Swedish postal codes. The rare 
combination of requests for this certificate type and the Swedish organization 
was the main reason for not detecting the bug before.

We identified a bug in the application causing the formatting error in postal 
code field for Swedish addresses. This has been fixed and verified.

We introduced an additional check in our certificate issuance system to 
identify any errors in the formatting of the postalCode field as described in a 
previous Incident with a similar error – see [1]. Unfortunately, this check was 
not activated for this specific type of certificates. We will ensure that this 
system control will cover all certificates such that any formatting error in 
the postalCode will interrupt the certificate issuance.



