Consorci AOC: Qualified audit statements
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: wthayer, Assigned: fferre)
Details
(Whiteboard: [ca-compliance] [audit-failure])
Attachments
(5 files)
Updated•7 years ago
|
| Assignee | ||
Comment 1•7 years ago
|
||
| Assignee | ||
Comment 2•7 years ago
|
||
| Assignee | ||
Comment 3•7 years ago
|
||
| Assignee | ||
Comment 5•7 years ago
|
||
| Assignee | ||
Comment 6•7 years ago
|
||
| Reporter | ||
Comment 7•7 years ago
|
||
| Assignee | ||
Comment 8•7 years ago
|
||
| Reporter | ||
Comment 9•7 years ago
|
||
| Assignee | ||
Comment 10•7 years ago
|
||
(In reply to Wayne Thayer [:wayne] from comment #9)
(In reply to Francesc Ferrer from comment #8)
When the subCA was created back in 2014, a decision based on simplicity put
the end-entity signature certificates and end-entity web authentication
together into this SubCA scope. As far as we know, at that moment the
restriction for not allowing suspended SSL certificates to be in the CRL was
not into place. When the restriction for SSL arised, controls were put into
place for not allowing SSL certs suspension. This controls have passed
already a few audits and are working fine. Therefore, Consorci AOC is asking
for legacy-mercy mesures for having non-SSL certificates suspended cert into
the EC-SectorPublic's CRL. It is absolutely clear for Consorci that new
Roots and SubCAs will need to be technically constrained with purpouse flags
and the SSL and signature certs must be separated into diferent subCAs.Thank you Francesc for this information. I think that this should be
discussed on the mozilla.dev.security.policy list. Before I begin that
discussion, can you confirm that Consorci has no plans to remediate this
problem, such as by moving new TLS issuance to a technically constrained
intermediate CA?
I can confirm that Consorci AOC do have plans for remediating this problem by creating a new set of roots and subCAs with the state of the art in terms of security and compliance (technically constrained and business scopes divided, in particular) by mid-2019 and that should start new TLS issuance with this new and technically constrainted root and intermediate CA exclusively for web authentication certificates by the end of the year. Another entire hierachy would be dedicated to eSignature and eSeals.
Please bear in mind that Consorci AOC is a public entity/government CA externaly operated and that the actual contract does not directly allow us to issue a new subCA immediately. A new contract is due to start by mid 2019 with the requirements stated above.
| Reporter | ||
Comment 11•7 years ago
|
||
Given the information provided in comment #10, the remediation for this incident is for Consorci to migrate all issuance to a new hierarchy, and I think that is good. The amount of time required to make that transition while continuing to violate the BRs is a problem. For now, I have marked this bug as requiring an update in January 2020.
| Assignee | ||
Comment 12•7 years ago
|
||
| Assignee | ||
Comment 13•7 years ago
|
||
Comment 14•7 years ago
|
||
We're now at a midpoint to the migration. Can you confirm the migration is on track as scheduled? Did the new contract, from Comment #10, get successfully executed?
| Assignee | ||
Comment 15•7 years ago
|
||
(In reply to Ryan Sleevi from comment #14)
We're now at a midpoint to the migration. Can you confirm the migration is on track as scheduled? Did the new contract, from Comment #10, get successfully executed?
Due to significant changes in the plan stated in Comment#10, an updated version of the plan is provided:
- Due to contracting issues and restrictions, the new contract for the operation of Consorci AOC’s certification services with the new requirements will not start until Jan 2020 instead of mid-2019 as stated before. Please bear in mind that Consorci AOC is a Government entity and, therefore, strict contracting procedures apply.
- Due to the delay stated above Consorci AOC decided a few months ago and before the recent audit, to stop issuing SSL certificates by the end of 2019. Communication to customers was sent a few weeks ago and it can be found here. End-entity SSL Issued certs and its issuing subCAs and infrastructure will still be maintained until all end-entity certs expired.
- In parallel, Consorci AOC is requiring a new set of roots and subCAs in the new contract in order to move all the issuance of eSignature and eSeal certificates in conformance to EIDAS and CCADB Program (for email trust bit enabled only) by mid-2020.
| Assignee | ||
Comment 16•7 years ago
|
||
Sorry, this is the link to the communication to clients: https://www.aoc.cat/2019/04/02/consorci-aoc-deixa-demetre-certificats-de-servidor-segur-ssl/
Updated•7 years ago
|
| Reporter | ||
Comment 17•7 years ago
|
||
Francesc:
The audit statements provided in comments 1 and 13 contain yet more non-conformities. Have these been remediated?
Due to the delay stated above Consorci AOC decided a few months ago and before the recent audit, to stop issuing SSL certificates by the end of 2019. Communication to customers was sent a few weeks ago and it can be found here. End-entity SSL Issued certs and its issuing subCAs and infrastructure will still be maintained until all end-entity certs expired.
Does Consorci intend to achieve and maintain full compliance with the BRs and Mozilla policy until all end-entity certificates expire, presumably in late 2021?
| Assignee | ||
Comment 18•6 years ago
|
||
(In reply to Wayne Thayer [:wayne] from comment #17)
Francesc:
The audit statements provided in comments 1 and 13 contain yet more non-conformities. Have these been remediated?
Assuming that you meant the comments corresponding the 2019 audits that are comments #12 (instead of #1) and #13, every non-confomity has been remediated in a plan provided to the auditor and accepted for it before statement's issuance. At the moment, 3 out of the all 12 minor Non-conformities have been already solved.
Due to the delay stated above Consorci AOC decided a few months ago and before the recent audit, to stop issuing SSL certificates by the end of 2019. Communication to customers was sent a few weeks ago and it can be found here. End-entity SSL Issued certs and its issuing subCAs and infrastructure will still be maintained until all end-entity certs expired.
Does Consorci intend to achieve and maintain full compliance with the BRs and Mozilla policy until all end-entity certificates expire, presumably in late 2021?
Yes, as stated in the communication to the costumers (translated by google from the text of the website above and slightly adjusted) : "The certificates issued until December 31, Consorci AOC will ensure the validity of the same during the two years of his term. "
Updated•6 years ago
|
Comment 19•6 years ago
|
||
Wayne: Looking at CT, it looks like the last certificate issued by EC-SectorPublic was on 2019-12-27.
I believe Mozilla was looking into the capability of disabling trust on a forward-looking basis (in Bug 1593141), so I wasn't sure if this was a use case for that, but I think it goes back to you as this CA is shutting down for TLS.
| Reporter | ||
Comment 20•6 years ago
|
||
Francesc: can you confirm that Consorci has stopped issuing TLS certificates from all subCAs signed by the EC-ACC root as of 2019-12-27?
Ryan: I think you're referring to bug 1465613 which affects the entire hierarchy.
| Assignee | ||
Comment 21•6 years ago
|
||
(In reply to Wayne Thayer [:wayne] from comment #20)
Francesc: can you confirm that Consorci has stopped issuing TLS certificates from all subCAs signed by the EC-ACC root as of 2019-12-27?
Yes, I can confirm that TLS certificates issuance finished by 2019-12-27 from all subCAs signed by the EC-ACC.
Having confirmed that, Consorci AOC assumes that CCADB trust in the already issued and still valid TLS certificates would last until its expiration in 2021-12-27 at latest. And, in particular, that e-mail trust bit trust for the EC-ACC root is going to remain active. Of course, by complying at all times with the Mozilla Root Store policy. If we are wrong in this assumption and trust configuration changes are going to be applied, please inform us in advance so we can handle the impact of them.
| Reporter | ||
Comment 22•6 years ago
|
||
(In reply to Francesc Ferrer from comment #21)
(In reply to Wayne Thayer [:wayne] from comment #20)
Francesc: can you confirm that Consorci has stopped issuing TLS certificates from all subCAs signed by the EC-ACC root as of 2019-12-27?
Yes, I can confirm that TLS certificates issuance finished by 2019-12-27 from all subCAs signed by the EC-ACC.
Thank you. This means that we can distrust certificates issued after that date. Adding N-I for Kathleen to process this distrust, after which I believe this bug may be resolved.
Having confirmed that, Consorci AOC assumes that CCADB trust in the already issued and still valid TLS certificates would last until its expiration in 2021-12-27 at latest.
Correct, all TLS certificates issued on or before 2019-12-27 will remain valid at this time and until they expire, assuming that Consorci remains in compliance with the Mozilla Root Store Policy.
And, in particular, that e-mail trust bit trust for the EC-ACC root is going to remain active.
The Mozilla email trust bit is not enabled for the EC-ACC root (https://searchfox.org/mozilla-central/source/security/nss/lib/ckfw/builtins/certdata.txt#11629)
Of course, by complying at all times with the Mozilla Root Store policy. If we are wrong in this assumption and trust configuration changes are going to be applied, please inform us in advance so we can handle the impact of them.
Comment 23•6 years ago
|
||
(In reply to Wayne Thayer from comment #22)
(In reply to Francesc Ferrer from comment #21)
(In reply to Wayne Thayer [:wayne] from comment #20)
Francesc: can you confirm that Consorci has stopped issuing TLS certificates from all subCAs signed by the EC-ACC root as of 2019-12-27?
Yes, I can confirm that TLS certificates issuance finished by 2019-12-27 from all subCAs signed by the EC-ACC.
Thank you. This means that we can distrust certificates issued after that date. Adding N-I for Kathleen to process this distrust, after which I believe this bug may be resolved.
I have filed Bug #1621159 to set CKA_NSS_SERVER_DISTRUST_AFTER to 12/28/2019 for this root:
Subject: CN=EC-ACC; OU=Serveis Publics de Certificacio, Vegeu https://www.catcert.net/verarrel (c)03, Jerarquia Entitats de Certificacio Catalanes; O=Agencia Catalana de Certificacio (NIF Q-0801176-I); C=ES
Certificate Serial Number: EE2B3DEBD421DE14A862AC04F3DDC401
SHA-1 Fingerprint: 28903A635B5280FAE6774C0B6DA7D6BAA64AF2E8
SHA-256 Fingerprint: 88497F01602F3154246AE28C4D5AEF10F1D87EBB76626F4AE0B7F95BA7968799
Comment 24•6 years ago
|
||
In comment #20, Wayne asked "Francesc: can you confirm that Consorci has stopped issuing TLS certificates from all subCAs signed by the EC-ACC root as of 2019-12-27?" Which subCAs were being used to issue TLS certificates? I would like to verify that no new TLS certificates have been issued.
| Assignee | ||
Comment 25•6 years ago
|
||
(In reply to Ben Wilson from comment #24)
In comment #20, Wayne asked "Francesc: can you confirm that Consorci has stopped issuing TLS certificates from all subCAs signed by the EC-ACC root as of 2019-12-27?" Which subCAs were being used to issue TLS certificates? I would like to verify that no new TLS certificates have been issued.
Dear Mr. Wilson, the one and only SSL issuing CA in EC-ACC hierachy was EC-SECTORPUBLIC : https://crt.sh/?caid=8050. Thank you,
Updated•6 years ago
|
Updated•3 years ago
|
Updated•3 years ago
|
Description
•