Sectigo / Web.com: inconsistent disclosure of externally-operated intermediate
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: agwa-bugs, Assigned: Robin.Alden)
References
Details
(Whiteboard: [ca-compliance] [disclosure-failure])
Sectigo has disclosed the following intermediates as being operated under the same CP/CPS as parent:
https://crt.sh/?sha256=5DCF76EC8C7A84D94C7C9BFFDE0C9D45389AC618D11D343BD6A5EBA5BFC6F438
https://crt.sh/?sha256=1F32401D449A0619F30800D11A4F502DB49E0B332423F778BD522991FB6E0147
https://crt.sh/?sha256=C445D7EAA6F236F4CFC23AD1C2F8403BF733AE87E0E6FF5892C926044370FB48
However, the same subject + SPKI is found in this Web.com root certificate, which has a different CP/CPS:
https://crt.sh/?sha256=15F0BA00A3AC7AF3AC884C072B1011A077BD77C097F40164B2F8598ABD83860C
Updated•6 years ago
|
Updated•6 years ago
|
Assignee | ||
Comment 1•6 years ago
|
||
(In reply to Andrew Ayer from comment #0)
Andrew,
Thanks for the report. I acknowledge receipt and we will look to get an answer to you next week.
Updated•6 years ago
|
Assignee | ||
Comment 2•6 years ago
|
||
I apologize for the slow response.
We have a response in preparation and I will publish it here as soon as I can. I expect that to be this week, but I will update this ticket no later than September 17th.
Assignee | ||
Comment 3•6 years ago
|
||
As we mentioned in [1], we updated the CCADB records for the cross-certificates we've issued to Web.com so that the Audit and CP/CPS details match what Web.com have disclosed for their self-signed CA.
In order that these issues are more apparent for ourselves and for all other program CAs, Rob added two new buckets to https://crt.sh/mozilla-disclosures:
- Disclosed, but with Inconsistent Audit details
- Disclosed, but with Inconsistent CP/CPS details
As Ryan mentioned in [2], both Sectigo and Web.com include this CA in their WebTrust audits.
As he also deduced, this is because Sectigo runs some "white label" services for Web.com. Web.com's auditors rely on our public audit reports and they also rely on the audit work for both organizations (Sectigo and Web.com) having been carried out by the same group (EY). This arrangement between Sectigo and Web.com has existed for 12 years or more.
Although Sectigo do not issue certificates on our own behalf from this CA our WebTrust audits and disclosures would have allowed us to do so and we are technically able to do so. However it is a better expression of the intended purpose of this CA that we show Web.com's CPS in our CCADB entry for this CA so we will continue to do that.
[1] https://www.mail-archive.com/dev-security-policy@lists.mozilla.org/msg12256.html
[2] https://www.mail-archive.com/dev-security-policy@lists.mozilla.org/msg12210.html
Comment 4•6 years ago
|
||
It appears that all questions have been answered and remediation is complete.
Updated•3 years ago
|
Updated•2 years ago
|
Description
•