Closed Bug 1472993 Opened 8 years ago Closed 7 years ago

Sectigo audit reports

Categories

(CA Program :: CA Documents, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED WORKSFORME

People

(Reporter: rob, Assigned: rob)

Details

(Whiteboard: [ca-audits])

Attachments

(9 files, 73 obsolete files)

1.44 MB, application/pdf
Details
109.47 KB, application/pdf
Details
340.45 KB, application/pdf
Details
1.77 MB, application/pdf
Details
1.73 MB, application/pdf
Details
1.38 MB, application/pdf
Details
826.96 KB, application/pdf
Details
579.84 KB, application/pdf
Details
646.60 KB, application/pdf
Details
We received our 2018 WebTrust audit reports on 28th June, which was shortly before the deadline (30th June) of 1y90d after the end of our previous audit period. However, we are still waiting for the cert.webtrust.org seal URLs to be provided to us, and so we have not yet submitted our updated audit information to the CCADB. I'm aware that https://ccadb.org/cas/updates says "If you don’t have a good place to put audit, CP and CPS documents, you can use Bugzilla", but I would argue that that doesn't apply in our case, because cert.webtrust.org is both a good place and the proper place to put WebTrust audit reports. Nonetheless, I will attach our 2018 WebTrust audit reports to this bug.
Attached file WebTrust_CA_Audit_Report.pdf (obsolete) —
Attached file WebTrust_Baseline_Audit_Report.pdf (obsolete) —
Attached file WebTrust_EVSSL_Audit_Report.pdf (obsolete) —
Why do these reports contain no mention of the misissuances (mostly around CAA) documented to have occurred during this audit period. Did Comodo disclose those to EY?
Flags: needinfo?(Rob.Stradling)
Hi Wayne. I'll ask our compliancy team to consider your question. BTW, since 28th June our compliancy team has been chasing our auditors on a daily basis, but we are _still_ waiting for the cert.webtrust.org seal URLs to be provided to us.
Our new WebTrust seals have at last been provided to us! CA: https://www.cpacanada.ca/webtrustseal?sealid=10006 BR: https://www.cpacanada.ca/webtrustseal?sealid=10009 EV SSL: https://www.cpacanada.ca/webtrustseal?sealid=10007 EV Code Signing: https://www.cpacanada.ca/webtrustseal?sealid=10008 Our auditor just told us that "CPA Canada was the reason for the delay, per their apology". No further detail was provided to us, but I have made some observations... Starting sometime yesterday, I noticed that all cert.webtrust.org seal URLs are now being redirected to www.cpacanada.ca. This suggests that there's just been some sort of migration/overhaul of the WebTrust seal hosting system, and I suspect that this is the real reason for the delay in delivering our new seal URLs. Also, I'm surprised to see that our new "sealid" values are in the 10000+ range. I don't know why WebTrust have stopped sequentially allocating new "sealid" values in the ~2500 range, but presumably it's related to this migration/overhaul. Problem #1: Seal URLs on www.cpacanada.ca cannot be accessed directly. If you try pasting any of our new seal URLs (see above) into your browser's address bar, you'll arrive at a page that simply says "Not a valid domain for this seal". This affects *all* existing cert.webtrust.org seal URLs (due to the new redirection behaviour), which (by my count) affects 186 of the 426 root certificate records on the CCADB. Seal URLs on www.cpacanada.ca can only be accessed when the HTTP Referer request header contains an "authorized domain". Since "comodoca.com" is one of our authorized domains, I just threw together https://sslanalyzer.comodoca.com/webtrust.html to demonstrate this. (You won't get the "Not a valid domain for this seal" error if you access our new seals by clicking on the links on that page). We've asked our auditors to find out if this problem can be fixed, or if it's intended behaviour. I hope it can be fixed, because it's also broken all WebTrust audit links (provided by CCADB) on crt.sh certificate pages. Problem #2: Previously, WebTrust seal boilerplate pages could be accessed directly via https://cert.webtrust.org/ViewSeal?id=XXXX, and the PDF audit report documents could be accessed directly via https://cert.webtrust.org/SealFile?seal=XXXX&file=pdf. However, the "Click here to view the Audit Report and Management's Assertions" links on www.cpacanada.ca seal boilerplate pages are not simple links; instead, they execute Javascript to trigger the download of the PDF. Viewing the source of our new seal boilerplate pages revealed that our PDF audit reports can actually be downloaded directly from the following URLs: CA: https://www.cpacanada.ca/GenericHandlers/AptifyAttachmentHandler.ashx?AttachmentID=221708 BR: https://www.cpacanada.ca/GenericHandlers/AptifyAttachmentHandler.ashx?AttachmentID=221711 EV SSL: https://www.cpacanada.ca/GenericHandlers/AptifyAttachmentHandler.ashx?AttachmentID=221709 EV Code Signing: https://www.cpacanada.ca/GenericHandlers/AptifyAttachmentHandler.ashx?AttachmentID=221710 So now I think I just need to figure out whether or not these URLs are "a good place to put audit...documents"!
[Redirecting NEEDINFO to Robin] Robin, when you can, please answer Wayne's question (see comment 5). Thanks.
Flags: needinfo?(Rob.Stradling) → needinfo?(robin)
We asked our auditor (on 18th July) to find out: 1. if WebTrust / CPA Canada intend to fix any of the problems identified in comment 7 and 2. if the URLs at the end of comment 7 are "a good place" for audit reports We've not received any response. Clearly we can't keep waiting forever, since it's now over 3 weeks since we needed to submit our annual audit reports to the CCADB. Therefore, we're going to have to take the view that the new WebTrust seal URL behaviour is probably intentional and that therefore (despite how daft this sounds) the WebTrust seal service is no longer "a good place to put audit...documents". I will submit our annual audit reports to the CCADB today, using this bug's attachment URLs (as suggested/permitted by https://ccadb.org/cas/updates).
I've submitted a new case on the CCADB. The ALV tool complained... "Audit letter not found in certified location. Audit letter will be manually reviewed. Audit letter should be hosted by an approved certifying authority." So it would appear that WebTrust / CPA Canada have just broken at least one aspect of the CCADB's automatic audit letter validation process. i.e., the approved certifying authority (WebTrust / CPA Canada) is no longer willing to host WebTrust audit reports in a certified location. Wayne, Kathleen, Does this represent a significant problem? Do Mozilla and the other CCADB root store operators plan to reach out to WebTrust / CPA Canada to discuss this?
(In reply to Rob Stradling from comment #10) > Does this represent a significant problem? That's OK. It just means that I have to independently exchange email with the auditor to confirm the authenticity of the documents. > Do Mozilla and the other CCADB > root store operators plan to reach out to WebTrust / CPA Canada to discuss > this? I sent email to folks at cpacanada on July 19, but no one has responded yet. But I can still process the Audit Case. I don't see a response to Wayne's question in Comment #5...
(In reply to Wayne Thayer [:wayne] from comment #5) > Why do these reports contain no mention of the misissuances (mostly around > CAA) documented to have occurred during this audit period. Did Comodo > disclose those to EY? Robin: I'm still awaiting an answer to these questions. Please respond by 3-August 2018.
Wayne, Sorry for the slow response. I will work with our auditors to provide a full response. Regards Robin
Flags: needinfo?(robin)
Whiteboard: [ca-audits] - keep open until resolution to audit not noting known deviations
Hi Wayne, Sorry for the further delay and thanks for your patience so far. I will have a substantive reply for you by the end of this week. Regards Robin
> Why do these reports contain no mention of the misissuances (mostly around > CAA) documented to have occurred during this audit period. Did Comodo > disclose those to EY? It turns out that we did not disclose these to EY. That was down to Comodo CA not offering the evidence of these events during the audit evidence gathering phase. It was not our intention to mislead and we regret this short-coming on our part. We have amended our own internal audit process to make sure these are gathered up as part of the evidence pack to go to the auditors in future audit cycles.
Closing this bug. It can be used to share future Comodo audit reports with Mozilla.
Status: NEW → RESOLVED
Closed: 7 years ago
QA Contact: kwilson
Resolution: --- → FIXED
Whiteboard: [ca-audits] - keep open until resolution to audit not noting known deviations → [ca-audits]
Summary: Comodo CA audit reports → Sectigo audit reports
Attached file Sectigo_WebTrust_CA.pdf (obsolete) —
Attachment #8989406 - Attachment is obsolete: true
Attached file Sectigo_WebTrust_BR.pdf (obsolete) —
Attachment #8989407 - Attachment is obsolete: true
Attached file Sectigo_WebTrust_EV_SSL.pdf (obsolete) —
Attachment #8989408 - Attachment is obsolete: true
Attached file Sectigo_WebTrust_EV_Code_Signing.pdf (obsolete) —
Attachment #8989409 - Attachment is obsolete: true
Attached file Sectigo_WebTrust_OV_Code_Signing.pdf (obsolete) —
Attached file Sectigo_WebTrust_CA.pdf (obsolete) —

s/formally/formerly/

Attachment #9074728 - Attachment is obsolete: true
Attached file Sectigo_WebTrust_BR.pdf (obsolete) —

s/formally/formerly/

Attachment #9074729 - Attachment is obsolete: true
Attached file Sectigo_WebTrust_EV_SSL.pdf (obsolete) —

s/formally/formerly/

Attachment #9074730 - Attachment is obsolete: true
Attached file Sectigo_WebTrust_EV_Code_Signing.pdf (obsolete) —

s/formally/formerly/

Attachment #9074731 - Attachment is obsolete: true
Attached file Sectigo_WebTrust_OV_Code_Signing.pdf (obsolete) —

s/formally/formerly/

Attachment #9074732 - Attachment is obsolete: true

Reopening per email from Rob.

Status: RESOLVED → REOPENED
Resolution: FIXED → ---
Attached file Sectigo_WebTrust_CA.pdf (obsolete) —

Fixed the audit period dates in the Management Assertion.

Status: REOPENED → RESOLVED
Closed: 7 years ago7 years ago
Resolution: --- → FIXED
Attached file 2020 - Sectigo - WebTrust for CAs (obsolete) —
Attached file 2020 - Sectigo - WebTrust EV SSL (obsolete) —
Attached file Sectigo-WebTrust_CA.pdf (obsolete) —
Attachment #9075093 - Attachment is obsolete: true
Attachment #9161252 - Attachment is obsolete: true
Attached file Sectigo-Webtrust_SSLBaseline.pdf (obsolete) —
Attachment #9075094 - Attachment is obsolete: true
Attachment #9161258 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_EVSSL.pdf (obsolete) —
Attachment #9075096 - Attachment is obsolete: true
Attachment #9161256 - Attachment is obsolete: true
Attached file Sectigo-Webtrust_PTCodeSigning.pdf (obsolete) —
Attachment #9075098 - Attachment is obsolete: true
Attachment #9161257 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_EVCodeSigning.pdf (obsolete) —
Attachment #9075097 - Attachment is obsolete: true
Attachment #9161254 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_CA.pdf (obsolete) —
Attachment #9078178 - Attachment is obsolete: true
Attachment #9179595 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_CA_2021.pdf (obsolete) —
Attachment #9179600 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_BRSSL_2021.pdf (obsolete) —
Attachment #9179596 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_EVSSL_2021.pdf (obsolete) —
Attachment #9179597 - Attachment is obsolete: true
Attachment #9179598 - Attachment is obsolete: true
Attachment #9179599 - Attachment is obsolete: true

Rob: Thanks for sharing Comment #41, Comment #42, and Comment #43

You may wish to draw to attention to your auditors that the document titles in the PDF are "SSLcom", while the documents themselves are addressed to Sectigo management.

It would be useful to understand how and why this occurred.

Flags: needinfo?(rob)

Thanks Ryan. Good catch. We see that the WTCA report (comment #40) has the same problem. We've sent an enquiry to our auditors.

A couple of initial thoughts on why we missed this in our review of the draft reports:

  • It appears that our previous auditor did not use PDF document titles at all, so our review process wasn't expecting them. We'll be adding a step to check PDF document titles in our going-forward review process.
  • Several colleagues are telling me that their PDF readers either don't show PDF document titles by default or are completely unable to show them.
Flags: needinfo?(rob)

Ryan: It looks like Chrome displays the title from the meta data in the PDF if a document title is present, rather than the file name. The PDF meta data is inherited from the original Microsoft Word document, rather than the file name. This title is not readily visible, unless you open the file in Chrome or inspect the meta data of the PDF. If a Word document of another report is used as a template for a new report, that meta data is carried forward, even after the file name has been updated and all readily visible changes have been made. This will be something we check in the future.

Attached file Sectigo-WebTrust_CA_2021.pdf (obsolete) —
Attachment #9229486 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_BRSSL_2021.pdf (obsolete) —
Attachment #9229487 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_EVSSL_2021.pdf (obsolete) —
Attachment #9229488 - Attachment is obsolete: true
Attachment #9229490 - Attachment is obsolete: true

Thanks Tim.

Ryan: In comments 47, 48, 49, 50 I've attached new versions of our WebTrust reports in which the misleading document titles have been stripped.

Resolution: FIXED → WORKSFORME
Attached file Sectigo-WebTrust_CA_2022.pdf (obsolete) —
Attachment #9231131 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_BRSSL_2022.pdf (obsolete) —
Attachment #9231132 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_EVSSL_2022.pdf (obsolete) —
Attachment #9231133 - Attachment is obsolete: true
Attachment #9231134 - Attachment is obsolete: true
Attachment #9283205 - Attachment is obsolete: true
Component: CA Certificate Root Program → CA Documents
Product: NSS → CA Program
QA Contact: kwilson
Version: trunk → unspecified

PDF saved w/o digital signatures

ALV testing date format

Attachment #9319109 - Attachment is obsolete: true
Attachment #9319105 - Attachment is obsolete: true
Attachment #9319111 - Attachment is obsolete: true
Attachment #9319104 - Attachment is obsolete: true
Attached file |DRAFT|Sectigo-WebTrust_CA_2023.pdf (obsolete) —
Attached file |DRAFT|Sectigo-WebTrust_BRSSL_2023.pdf (obsolete) —
Attached file |DRAFT|Sectigo-WebTrust_EVSSL_2023.pdf (obsolete) —
Attachment #9338897 - Attachment is obsolete: true
Attachment #9338899 - Attachment is obsolete: true
Attachment #9338900 - Attachment is obsolete: true
Attachment #9338901 - Attachment is obsolete: true
Attached file |DRAFT|Sectigo-WebTrust_CA_2023.pdf (obsolete) —
Attached file |DRAFT|Sectigo-WebTrust_BRSSL_2023.pdf (obsolete) —
Attached file |DRAFT|Sectigo-WebTrust_EVSSL_2023.pdf (obsolete) —
Assignee: kwilson → martijn.katerbarg
Attached file Sectigo-WebTrust_CA_2023.pdf (obsolete) —
Attached file Sectigo-WebTrust_BRSSL_2023.pdf (obsolete) —
Attached file Sectigo-WebTrust_EVSSL_2023.pdf (obsolete) —
Attachment #9283201 - Attachment is obsolete: true
Attachment #9283202 - Attachment is obsolete: true
Attachment #9283203 - Attachment is obsolete: true
Attachment #9283349 - Attachment is obsolete: true
Attachment #9339578 - Attachment is obsolete: true
Attachment #9339579 - Attachment is obsolete: true
Attachment #9339580 - Attachment is obsolete: true
Attachment #9339581 - Attachment is obsolete: true
Assignee: martijn.katerbarg → rob
Attached file Sectigo-WebTrust_CA_2024.pdf (obsolete) —
Attachment #9340908 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_BRSSL_2024.pdf (obsolete) —
Attachment #9340909 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_EVSSL_2024.pdf (obsolete) —
Attachment #9340910 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_CodeSigning_2024.pdf (obsolete) —
Attachment #9340911 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_SMIME_2024.pdf (obsolete) —
Attached file Sectigo-WebTrust_NSR_2024.pdf (obsolete) —
Attached file Sectigo-WebTrust_CA_2025.pdf (obsolete) —
Attachment #9409366 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_NSR_2025.pdf (obsolete) —
Attachment #9409372 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_BRSSL_2025.pdf (obsolete) —
Attachment #9409367 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_EVSSL_2025.pdf (obsolete) —
Attachment #9409368 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_CodeSigning_2025.pdf (obsolete) —
Attachment #9409369 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_SMIME_2025.pdf (obsolete) —
Attachment #9409370 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_CA_2026.pdf (obsolete) —
Attachment #9496930 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_NSR_2026.pdf (obsolete) —
Attachment #9496931 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_BRSSL_2026.pdf (obsolete) —
Attachment #9496932 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_EVSSL_2026.pdf (obsolete) —
Attachment #9496933 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_CodeSigning_2026.pdf (obsolete) —
Attachment #9496934 - Attachment is obsolete: true
Attached file Sectigo-WebTrust_SMIME_2026.pdf (obsolete) —
Attachment #9496935 - Attachment is obsolete: true
Attachment #9601392 - Attachment is obsolete: true
Attachment #9601393 - Attachment is obsolete: true
Attachment #9601395 - Attachment is obsolete: true
Attachment #9601396 - Attachment is obsolete: true
Attachment #9601397 - Attachment is obsolete: true
Attachment #9601403 - Attachment is obsolete: true
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: