D-TRUST: Non-BR-Compliant Certificate Issuance
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: kathleen.a.wilson, Assigned: browser-ca)
References
Details
(Whiteboard: [ca-compliance] [ov-misissuance] [ev-misissuance] [policy-failure])
| Assignee | ||
Comment 1•8 years ago
|
||
Comment 2•8 years ago
|
||
Comment 3•8 years ago
|
||
Updated•8 years ago
|
| Assignee | ||
Comment 4•8 years ago
|
||
Comment 5•8 years ago
|
||
| Assignee | ||
Comment 6•8 years ago
|
||
Comment 7•8 years ago
|
||
| Assignee | ||
Comment 8•8 years ago
|
||
Comment 9•8 years ago
|
||
Comment 10•8 years ago
|
||
Updated•8 years ago
|
Comment 11•8 years ago
|
||
Comment 12•8 years ago
|
||
Updated•8 years ago
|
Comment 13•8 years ago
|
||
Comment 14•8 years ago
|
||
Updated•8 years ago
|
Comment 15•8 years ago
|
||
Comment 16•8 years ago
|
||
Updated•8 years ago
|
Comment 17•8 years ago
|
||
Comment 18•8 years ago
|
||
Comment 19•8 years ago
|
||
Comment 20•8 years ago
|
||
Comment 21•8 years ago
|
||
Comment 22•8 years ago
|
||
Comment 23•8 years ago
|
||
Comment 24•8 years ago
|
||
Comment 25•7 years ago
|
||
Comment 26•7 years ago
|
||
Comment 27•7 years ago
|
||
Updated•7 years ago
|
Comment 28•7 years ago
|
||
Enrico: Do you have any updates?
Comment 29•7 years ago
|
||
Ryan: Enrico is out of Office right now, we will respond shortly with an update. Sorry for the delay! Kim
Comment 30•7 years ago
|
||
Thank you for bringing this up. Sorry for the delay.
The actual status is that all effected certificates are revoked. We got the permission to publish some of the certificates to CT-logs, which will happen soon.
I will inform as soon as this is finished.
Comment 32•7 years ago
|
||
The upload of the certificates is planned for next week.
Comment 34•7 years ago
|
||
We had the permission to publish 150 certificates to ct logs. The upload has been successfully completed on 2019/01/24 and 2019/01/25. The certificates are now public on 4 ct logs (https://ct1.digicert-ct.com/log, https://mammoth.ct.comodo.com, https://ct.googleapis.com/pilot, https://ct.googleapis.com/rocketeer). These are the references to crt.sh:
https://crt.sh/?id=1143495973&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495429&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495446&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143496436&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495945&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495839&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495261&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495265&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495263&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495262&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495230&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495239&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495247&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495241&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495250&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495433&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495090&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495096&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494941&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495091&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494463&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494721&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494117&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494103&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494074&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494127&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494777&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494007&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494078&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143494011&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143495238&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493879&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493986&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493976&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493497&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493494&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493940&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493463&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493499&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493474&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493491&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493450&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493452&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493440&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493455&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493425&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493426&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493457&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493277&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493400&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493430&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493434&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493114&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143493445&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143492615&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491969&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143492061&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491985&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491991&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491398&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491436&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491430&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491250&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491343&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491319&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491393&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490806&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490784&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490794&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143491189&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490796&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490780&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490765&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490636&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490764&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490608&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490613&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490390&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490600&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490405&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490287&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489715&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490270&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489710&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489713&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489723&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143490435&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489222&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489144&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489225&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488946&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489140&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489134&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488914&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488942&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489118&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488811&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488896&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143489110&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488870&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488839&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488965&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143487773&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488865&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488337&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143487793&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143487741&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143487696&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143487624&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488410&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143488248&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143487661&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486181&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143487573&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486111&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486225&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143487553&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486146&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486179&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486108&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486138&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486193&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486105&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486096&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486107&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486083&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486097&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486234&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486211&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486089&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486148&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486210&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484615&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484567&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484621&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486039&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486027&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143486018&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484593&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484559&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484572&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484584&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484591&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484628&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484633&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484555&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484553&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1143484530&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1141081759&opt=cablint,x509lint,zlint,
https://crt.sh/?id=1140335835&opt=cablint,x509lint,zlint,
Updated•7 years ago
|
Comment 35•7 years ago
|
||
Wayne: Comment #34 slipped through the cracks in light of everything. That has a disclosure of 150 certificates, less than the 261 certificates requested in Comment #22. I'll punt this to you to decide whether to close, and/or whether further explanations and process mitigations are necessary by D-TRUST regarding future incidents (see Comment #18 / Comment #19)
Comment 36•7 years ago
|
||
The response to this incident by D-TRUST has been deficient, especially with respect to the time it took to replace the defective certificates. It should be clear that Mozilla expects faster remediation in the future.
Enrico: Is there anything more that you can share to reassure us that D-TRUST's response will be better next time?
Comment 37•7 years ago
|
||
Wayne: First of all, I want to assure you that we regret this long period of revocation very much. We have learned our lessons. We adopted and implemented extensive measures to deal with the incident to prevent such delays in the future.
From our point of view, the facts of the case are as follows:
Unfortunately, the complete revocation of all certificates with short serial numbers issued after September 30, 2016 could only be completed by D-TRUST on July 16, 2018.
Most of the certificates were used in infrastructures, which customers described as complex and mission critical. Therefore, the revocation took place in several steps and in close coordination with the affected customers.
A) Revocation of certificates
From September 30, 2016 to May 15, 2017 63 EV TLS certificates and until July 07, 2017 607 OV TLS certificates with short serial numbers were issued. Of these, 409 certificates were revoked and replaced by December 31, 2017.
As of January 01, 2018, 261 certificates with short serial numbers had not yet been revoked. According to our customers, these were used in sensitive and highly complex infrastructures. We revoked the certificates in close cooperation with our customers until July 16, 2018.
B) Publication of certificates that were revoked in 2018
The hash values of all 261 certificates that were revoked in 2018 were published by us in order to create transparency. 150 of these certificates were published in CT logs. For 111 certificates, there is no customer approval for publication due to the contract. Therefore, no publication in a CT log has taken place here so far. We ask for your understanding for this situation.
What steps has D-TRUST taken to prevent such a delay in the revocation of defective certificates in the future?
As already mentioned, the entire incident has been extensively analyzed and measures have been taken to prevent such a delay in the revocation of defectively issued certificates in the future and to ensure that the certificates are revoked within the times specified by the BRs.
-
Expansion of the PKI team
The team to assess certificate incidents and respond immediately has been significantly expanded. In addition, the content of the training of the support team, especially on the subject of certificate incidents, was expanded and the team was trained accordingly. -
Optimization of internal and external processes for the revocation of defective certificates
The internal and external processes for processing defective certificates and certificate incidents were revised and optimized. In addition, significant changes were made to communication on the website and in customer documents. -
Contractual optimization/ revision of obligation to revoke and the customer's obligation to cooperate
The contract documents have been optimized in such a way that it is particularly clear that the customer has a duty to cooperate and that the CA has an obligation to revoke in accordance with the BRs in certain time windows. -
Proactive customer communication regarding the CA's obligation to revoke and the associated risks for the customer's IT operations
We have again informed our existing customers about our obligation to revoke and drawn their attention to the risk to their IT operations if we have to revoke defective certificates within the revocation periods of the BRs. We have asked our customers to take precautionary measures.
With these measures, we want to ensure that the revocation periods in accordance with the BRs are adhered to in future.
Comment 38•7 years ago
|
||
Enrico: Thank you for this informative response. I now believe that all questions have been answered and this issue has been resolved.
Updated•3 years ago
|
Updated•3 years ago
|
Description
•