DigiCert: Underscores - CVS Pharmacy
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: jeremy.rowley, Assigned: brenda.bernal)
References
Details
(Whiteboard: [ca-compliance] [ov-misissuance])
Comment 1•7 years ago
|
||
Comment 2•7 years ago
|
||
| Assignee | ||
Comment 4•7 years ago
|
||
Comment 5•7 years ago
|
||
| Assignee | ||
Comment 6•7 years ago
|
||
Comment 7•7 years ago
|
||
| Reporter | ||
Comment 8•7 years ago
|
||
Comment 9•7 years ago
|
||
| Reporter | ||
Comment 10•7 years ago
|
||
Comment 11•7 years ago
|
||
Updated•7 years ago
|
| Reporter | ||
Comment 12•7 years ago
|
||
Based on the conversation on the forum, the post from Wayne, and instruction from Google, our understanding is there is no exception or extension possible and the expectation is that all CAs will revoke the certificates on the date required by the BRs. We hope that the same rules/penalties/expectations will be applied to those CAs who fail to revoke on the required date. Thank you for the discussion. Although we were hoping for more compassionate results, we do appreciate the feedback and clarification on expectations.
| Reporter | ||
Comment 13•7 years ago
|
||
Seems there was a mis-communication on the intent of the discussions. We will post an update answering Ryan's questions tomorrow. Please ignore my previous post. Apologies for the confusion.
| Assignee | ||
Comment 14•7 years ago
|
||
In reply to Ryan's prompt on comment #11, here's the response back to the following:
For example, from the timeline, we know that migration starts 02-15 and is expected to complete by 04-01 - meaning 6 weeks
to both replace certificates and rename hosts. In that time, the expectation is that hosts will be renamed, certificates
replaced, and acceptance testing performed. What's missing from that, which Wayne's questions got to, is "Are you saying
there is no way to replace certificates from 10-15 to 02-01" - that is, replace the certificates, not rename the hosts.
Customer response:
"It’s just as much work AND risk to both change the name of and replace a cert as it is to just replace the cert, because in both cases we’re “touching” the application that relies on the cert – which means application testing in non-production before the cert replacement, and in production after the cert replacement. Any touch to core PBM application now, in the heart of welcome season, constitutes significant, inadvisable, risk."
The customer is mitigating the risk of loss of customer service and benefits disruption during the busiest time of the annual enrollment period.
Comment 15•7 years ago
|
||
That risk assessment is surprising and somewhat against what would result from common industry practice. It is hoped that any remediation plan, if an incident occurs, will detail how such a situation will be mitigated in the future.
For example, past incidents have revealed a number of possible options:
- Migration to a private (non-BR audited) PKI
- The use and adoption of certificate automation, such that acceptance testing is not tied to individual certificates (a similar concern with pinning)
- The use of TLS intermediary devices (reverse proxies) that support more rapid upgrade and deployment, as explored through the SHA-1 and Symantec deprecations
While the BRs have long had an industry-standard, CA-agnostic revocation requirement, ultimately, the CA is responsible for making the decision to revoke or not revoke. It is hoped that a CA that makes a decision not to revoke will take concrete steps to prevent a reoccurrence in the future and identify concrete steps that they will take to ensure that.
Comment 16•7 years ago
|
||
Jeremy: Can you confirm whether an incident occurred and ensure that all of the details of affected certs are accurate?
| Assignee | ||
Comment 17•7 years ago
|
||
Hi Ryan, I will be responding to provide updates on the underscore incidents. I can confirm that an incident has occurred and the details provided are accurate to the best of our knowledge. Our planned extension to revoke the remaining certificates (listed above) is 31-May-2019. We will provide periodic updates as progress is made.
Comment 18•7 years ago
|
||
Brenda: I believe that date is different than the past discussions, and so want to understand how this target moved.
Comment #0 stated:
They plan on replacing all certificates by April 30th
Comment #4 stated:
target completion of the certificate swaps by the end of March
Comment #6 stated:
2019-04-01: No new underscore certificates are needed or will be issued
So now I'm trying to understand Comment #17:
Our planned extension to revoke the remaining certificates (listed above) is 31-May-2019
| Assignee | ||
Comment 19•7 years ago
|
||
Hi Ryan, I will say the 31-May-2019 is an error on my part. I meant to align it to the March 31st date. With that said, I'd like to report that the customer has made significant progress and Digicert plans to revoke their remaining underscores by Friday, February 8, 2019.
Updated•7 years ago
|
Updated•7 years ago
|
| Assignee | ||
Comment 20•7 years ago
|
||
The remaining underscore certificates listed above in Jeremy's initial report were all revoked as of today, February 8, 2019.
Comment 21•7 years ago
|
||
Thanks for the update, Brenda. I'm glad to hear this was resolved more timely than the originally proposed March 31.
I spot-checked a dozen, and they all show revoked, so I'm going to close this issue as Resolved, tagging Wayne in case he has any questions.
Updated•7 years ago
|
Updated•3 years ago
|
Updated•3 years ago
|
Description
•