Certinomis: test certificate for test.com, O=Entreprise TEST
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: agwa-bugs, Assigned: marc.maitre)
Details
(Whiteboard: [ca-compliance] [ov-misissuance])
Attachments
(1 file)
190.82 KB,
application/pdf
|
Details |
Comment 1•7 years ago
|
||
Updated•7 years ago
|
Comment 2•7 years ago
|
||
Comment 3•7 years ago
|
||
Comment 4•7 years ago
|
||
Comment 5•7 years ago
|
||
Comment 6•7 years ago
|
||
Comment 7•7 years ago
|
||
Comment 8•7 years ago
|
||
Reporter | ||
Comment 9•7 years ago
|
||
Reporter | ||
Comment 10•7 years ago
|
||
Comment 11•7 years ago
|
||
Comment 12•7 years ago
|
||
Comment 13•7 years ago
|
||
Comment 14•7 years ago
|
||
Marc: It's been nearly two weeks. Do you have an update?
Comment 15•7 years ago
|
||
Marc: Checking to see for updates?
Updated•7 years ago
|
Comment 16•7 years ago
|
||
Marc: It's been one month. Do you have updates?
Comment 17•6 years ago
|
||
Francois: I kindly request an immediate update on this incident.
Comment 18•6 years ago
|
||
Hello,
The development that implements domain validation in the workflow has been delivered.
It is now running on pre-production platform for testing.
If nothing is wrong it should be installed on production plaform within 3 weeks.
Kind Regards,
François
Updated•6 years ago
|
Comment 19•6 years ago
|
||
Has "domain validation in the workflow" been installed in production yet?
Reporter | ||
Comment 20•6 years ago
|
||
Here's another certificate with O=Entreprise TEST in the subject:
https://crt.sh/?sha256=97C78F92745645FE7ABC5A531C27F4C29D54F193563FB2035C01A0BE74CA3BBA
It was issued in January - after Certinomis indicated in comment 11 that the Entreprise TEST account had been configured to use a non-public CA - and it is still unrevoked today.
Comment 21•6 years ago
|
||
Dear Andrew,
Franck did not write false, and he really moved "Entreprise test" in a "demo zone" where only non PTC are available.
But he did half the job.
Indeed, there is two different access in our RA services for a certificate request: "normal" procedure is that a customer enter a request in "Front-Office" access that is afterward controlled and validated by a RA operator. And there is also the possibility for a RA operator to enter directly a request in a back-office access. This second possibility is for customer service purposes, and is also used for issuing test certificates.
What happened in last November is that Franck moved "Entreprise test" in a "demo zone" where only non PTC are available. This affects Front-Office access. But settings in back-office and front office are not bijective which means that a restriction applied in front office is not automatically transferred in back-office. So our full range of products remained available for "Entreprise test" in back-office access.
And it has been used in January for creating a new "test certificate".
Presently, entering certificate request in back-office access has been disabled for SSL certificates (on 25th of March).
It means that it is now impossible to create a certificate request in back-office access.
(Later a restricted back-office access will be re-opened only for external RA where domain name and Entreprise name are constrained)
In addition, everybody in Certinomis is now aware that test certificates are forbidden in SSL activity, contrary to what we practice for other certificates.
So you can be certain that you will not see another certificate with O= Entreprise test.
The certificate https://crt.sh/?id=1101522524 has been revoked on April, 18th, together with the certificate "expe.visio.douane.gouv.fr" mentioned in comment#11, and we have made a complete review of certificate issued for "Entreprise test" and have checked that they are now all revoked or expired.
Kind Regards,
François
Comment 22•6 years ago
|
||
Francois: did the complete review of certificate issued for "Entreprise test" find any certificates that hand not already been revoked?
Reporter | ||
Comment 23•6 years ago
|
||
I reported the following certificate in Comment 9, but at the time it seemed like its only problem was O=Entreprise TEST in the subject. It turns out it's also for an unregistered domain (seres-as2.fr):
https://crt.sh/?sha256=8f5e62db7d52ca96fb6e60924f9d11aad67958ef92a7bd46f0554b2eadead80e
I wanted to note this for completeness.
Comment 24•6 years ago
|
||
Dear Andrew,
Yes the core problem was the issuance of test certificate from PTC hierarchy.
And in test certificate not everything can be true.
This problem is now covered by isolating test account in a sepcial demio zone.
Kind Regards,
François
Comment 25•6 years ago
|
||
The Certinomis Root CA is being removed from the Mozilla root store in bug 1552374, so I am resolving this bug. Additional comments that may be useful when considering any future application by Certinomis are welcome.
Updated•3 years ago
|
Updated•2 years ago
|
Updated•1 year ago
|
Description
•