SwissSign: Misissuance of Intermediate Certificates because of incorrect organizationIdentifier
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: michael.guenther, Assigned: michael.guenther)
Details
(Whiteboard: [ca-compliance] [ca-misissuance])
Comment 1•7 years ago
|
||
Comment 2•7 years ago
|
||
Updated•7 years ago
|
| Assignee | ||
Comment 3•7 years ago
|
||
Updated•7 years ago
|
| Assignee | ||
Comment 4•7 years ago
|
||
| Assignee | ||
Comment 5•7 years ago
|
||
Updated•7 years ago
|
Updated•7 years ago
|
| Assignee | ||
Comment 6•7 years ago
|
||
Update
Search for similar flaws
In dual control we checked the parameters of our Issuing CAs with the documentation for each individual CA. Additionally, we also reviewed the available documentation (reason for the delay). The review resulted in a positive outcome.
Process improvements
We finished the review of the creation process for new issuing CAs and identified some additional points for improvements (such as additional dual controls during definition of the parameters). We believe that the changes improve the process as a whole. This process will be tested in the near future during the creation of a private Issuing CA.
Technical enforcement
We are adding a technical safeguard which ensures that only predefined profiles for organizationIdentifier can be selected. The definition of profiles is executed in dual control. The release of this safeguard is part of a release in Spring 2019.
We consider this ticket as resolved.
Thank you Mike
Comment 7•7 years ago
|
||
Mike: thank you for the update. Please update this bug when the technical safeguard has been deployed.
| Assignee | ||
Comment 8•6 years ago
|
||
With regret I have to report that the implementation might take up to end of May 2019.
The statement "New intermediate CAs will only be created if the technical safeguard is implemented" still holds.
Updated•6 years ago
|
| Assignee | ||
Comment 9•6 years ago
|
||
The technical safeguard (described in comment #6) has been successfully deployed to our productive systems on the weekend. With the last remediation done I ask that this incident is closed.
Comment 10•6 years ago
|
||
It appears that remediation has been completed.
Updated•3 years ago
|
Updated•3 years ago
|
Description
•