Closed
Bug 1369342
Opened 9 years ago
Closed 9 years ago
StartCom: 'un-revoking' intermediate certificates
Categories
(CA Program :: CA Certificate Compliance, task)
CA Program
CA Certificate Compliance
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: gerv, Assigned: kathleen.a.wilson)
Details
(Whiteboard: [ca-compliance] [uncategorized])
The following certificates were revoked by StartCom and then un-revoked (i.e. the entries were removed from the CRL and the OCSP servers were updated to resume returning 'good'):
https://crt.sh/?id=5403482
https://crt.sh/?id=6521559
https://crt.sh/?id=5707503
https://crt.sh/?id=6519052
These certificates were never added to OneCRL.
Un-revoking certificates is not permitted according to the BRs:
The BRs say...
"4.10. CERTIFICATE STATUS SERVICES
4.10.1. Operational Characteristics
Revocation entries on a CRL or OCSP Response MUST NOT be removed
until after the Expiry Date of the revoked Certificate."
"4.9.13. Circumstances for Suspension
The Repository MUST NOT include entries that indicate that a
Certificate is suspended."
Gerv
Hi,
as explained privately to Mozilla, in our remediation plan we stated that were going to cut any relationship with Wosign in order to follow the requirements set by the community and we had those cross-signed certificates still pending in the tasks list.
Then we let know Wosing of our intentions and acted accordingly revoking those certs. But some time later received a message from Microsoft asking for an issue regarding Azure that it was due to the recently revoked certificates for Wosign.
After some email exchanging, Microsoft requested us to un-revoke them to fix the issue with the Azure platform. We knew that was against BRs and standards, a revoked cert can´t be reinstated, but also knew that our "old" root certs were distrusted in all other platforms except Microsoft. Taking all this into account, we decided to follow Microsoft request because they were the only one affected.
Regards
| Assignee | ||
Updated•9 years ago
|
Whiteboard: [ca-compliance]
Comment 2•9 years ago
|
||
Gerv: I'm going to ask you to decide how to close this out. I don't think this fits within the response pattern of https://wiki.mozilla.org/CA/Responding_To_A_Misissuance , so I defer to you as to what information to collect, how to collect it, and whether that's sufficient.
Flags: needinfo?(gerv)
| Reporter | ||
Comment 3•9 years ago
|
||
I'm happy to let this go. If StartCom want to provide more information because they feel that it sheds new light on the situation, that's up to them. But otherwise, I think what happened is well understood.
Gerv
Status: NEW → RESOLVED
Closed: 9 years ago
Flags: needinfo?(gerv)
Resolution: --- → FIXED
Updated•3 years ago
|
Product: NSS → CA Program
Updated•3 years ago
|
Whiteboard: [ca-compliance] → [ca-compliance] [uncategorized]
You need to log in
before you can comment on or make changes to this bug.
Description
•