Closed Bug 1034837 Opened 10 years ago Closed 8 years ago

Micros: Issusing 1024 bit certificates

Categories

(CA Program :: CA Certificate Root Program, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: kurt, Assigned: kathleen.a.wilson)

References

Details

(Whiteboard: BR Compliance - 1024 bit certs)

Hi,

I'm seeing recent 1024 certificates from the following chain:
C = US, OU = www.xrampsecurity.com, O = XRamp Security Services Inc, CN = XRamp Global Certification Authority
C = US, ST = Illinois, L = Chicago, O = "Trustwave Holdings, Inc.", CN = "Trustwave Organization Issuing CA, Level 2", emailAddress = ca@trustwave.com
C = US, ST = Maryland, L = Columbia, O = "Micros Systems, Inc.", CN = Micros CA
C = US, ST = Maryland, L = Columbia, O = "Micros Systems, Inc.", CN = Micros Internal CA
Assignee: kwilson → jrandall
Whiteboard: BR Compliance - 1024 bit certs
jrandall: have you been able to look into this issue? If you need more info from Kurt about the certificates, you can ask here.

Gerv
Assignee: jrandall → kwilson
The last 1024 bit key issued from that chain was 8/14/14.  When Trustwave was made aware of the issue, we confirmed that this was specific to a particular use case and confirmed no other chains had improperly issued <2048 server certificates. Since then the "Trustwave Organization Issuing CA, Level 2" CA has been revoked.
Status: UNCONFIRMED → RESOLVED
Closed: 8 years ago
Resolution: --- → FIXED
Product: mozilla.org → NSS
Product: NSS → CA Program
You need to log in before you can comment on or make changes to this bug.