Closed
Bug 1266501
Opened 9 years ago
Closed 9 years ago
Certinga: certificate with invalid date format
Categories
(CA Program :: CA Certificate Root Program, task)
CA Program
CA Certificate Root Program
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: kurt, Assigned: j.allemandou)
References
Details
Attachments
(1 file)
|
39.55 KB,
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
|
Details |
Hi,
This certificate:
https://crt.sh/?id=16843038&opt=cablint,x509lint
Has the not valid after set using Generalized Time instead of UTCTime. It's doing it correctly for not valid before.
https://tools.ietf.org/html/rfc5280#section-4.1.2.5 clearly states that dates before 2050 should use UTCTime.
| Reporter | ||
Updated•9 years ago
|
Blocks: BR-Compliance
Updated•9 years ago
|
Assignee: kwilson → j.allemandou
| Assignee | ||
Comment 1•9 years ago
|
||
The problem has been identified by our teams and is being processed.
| Assignee | ||
Comment 2•9 years ago
|
||
We have identified and corrected the problem which concerned the renewal process on which an update has been applied in january. After control, we have identified the few certificates concerned by the use of « GeneralizedTime » in the field « Not after ». We are currently contacting the Certificate managers to operate the revocation and change of their certificate. We will informe you shortly when all certificates concerned will be replaced.
| Assignee | ||
Comment 3•9 years ago
|
||
Hi,
We wish to inform you that the majority of relevant certificates have already been replaced, including one designated in this bug.
We remain at your disposal for any further information.
Thank you in advance for your reply.
Updated•9 years ago
|
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Updated•8 years ago
|
Product: mozilla.org → NSS
| Assignee | ||
Comment 4•8 years ago
|
||
New version of our BR Self Assessment to integrate the updates relating to "DNS CAA" and "Certificate transparency".
Updated•3 years ago
|
Product: NSS → CA Program
You need to log in
before you can comment on or make changes to this bug.
Description
•