Closed
Bug 1266230
Opened 9 years ago
Closed 9 years ago
VR Ident EV certificate with multiple issues
Categories
(CA Program :: CA Certificate Root Program, task)
CA Program
CA Certificate Root Program
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: kurt, Assigned: sdavidson)
References
Details
(Whiteboard: BR Compliance)
This EV certificate has various issues:
https://crt.sh/?id=16930771&opt=x509lint
The subject is missing at least:
- a businessCategory
- the jurisdictionCountryName
- the serialNumber
The validity period is also slightly longer than the 27 months allowed by the EV requirements.
| Reporter | ||
Updated•9 years ago
|
Blocks: BR-Compliance
Comment 1•9 years ago
|
||
Stephen, Please work with QuoVadis' VR IDENT subCA to fix their EV SSL certificate issuance to be in line with the EV guidelines, and update this bug with status on getting this resolved. Also please look into why these problems weren't noticed by the auditor.
Assignee: kwilson → sdavidson
| Assignee | ||
Comment 2•9 years ago
|
||
Acknowledged. We will have certificate revoked, and revert with more information.
| Assignee | ||
Comment 3•9 years ago
|
||
Confirming that the certificate has been revoked. Will revert with details steps taken to prevent a recurrence.
| Assignee | ||
Comment 4•9 years ago
|
||
Apologies for the delay in responding.
The issue in question was intended to be an OV SSL, but due to an RA administrative error was issued using an EV policy.
In previous practice, EV policies were manually enabled for specific RA administrators at the time of EV issuance. During such a period, the assigned administrator chose the incorrect policy.
The certificate was never installed on a webserver; as it was issued using an EV policy it was automatically logged in CT.
During the investigation, the CA halted EV issuance while additional RA technical controls were implemented to prevent an OV request being delivered using an EV policy. Further control enhancements in the certificate administration tool will be implemented in the coming weeks.
The CA has informed its external auditor regarding the certificate, as well as changes to the RA process and certificate administration tool.
Comment 5•9 years ago
|
||
Stephen, Thank you for sharing the results of your investigation.
> Further control enhancements in the certificate
> administration tool will be implemented in the coming weeks.
What further control enhancements do you expect to be implemented?
What potential problems will those solve?
Were any other EV certs issued that should have been OV certs?
Comment 6•9 years ago
|
||
Stephen, any update on this?
Updated•9 years ago
|
Whiteboard: BR Compliance
| Assignee | ||
Comment 7•9 years ago
|
||
What further control enhancements do you expect to be implemented? What potential problems will those solve?
> Previously RAs manually processed certificate requests. The updated certificate administration tool includes template filters and workflows such that, among other things, only complete EV requests can be sent for signing using an EV policy. The certificate administration tool is intended to enforce aspects of the BR and EV Guidelines.
Were any other EV certs issued that should have been OV certs?
> No.
Comment 8•9 years ago
|
||
(In reply to Stephen Davidson from comment #7)
> What further control enhancements do you expect to be implemented? What
> potential problems will those solve?
> > Previously RAs manually processed certificate requests. The updated certificate administration tool includes template filters and workflows such that, among other things, only complete EV requests can be sent for signing using an EV policy. The certificate administration tool is intended to enforce aspects of the BR and EV Guidelines.
>
> Were any other EV certs issued that should have been OV certs?
> > No.
Thanks.
Looks like this bug has been resolved.
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Updated•8 years ago
|
Product: mozilla.org → NSS
Updated•3 years ago
|
Product: NSS → CA Program
You need to log in
before you can comment on or make changes to this bug.
Description
•