Closed Bug 1796715 Opened 3 years ago Closed 3 years ago

IdenTrust: Mis-Issued EV Code Signing Certificate

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: roots, Assigned: roots)

Details

(Whiteboard: [ca-compliance] [uncategorized])

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36

Steps to reproduce:

  1. How your CA first became aware of the problem (e.g. via a problem report submitted to your Problem Reporting Mechanism, a discussion in mozilla.dev.security.policy, a Bugzilla bug, or internal self-audit), and the time and date.

On 10/18/2022 we issued an EV Code Signing certificate to HydrantID, which upon post-issuance validation was discovered to have the wrong Serial Number for the Jurisdiction of State.

The EV code signing certificate was issued to the following subject:
C = US,
ST = Utah,
L = Salt Lake City,
serialNumber = 8987986-0143,
jurisdictionC = US,
jurisdictionST = Delaware,
businessCategory = Private Organization,
O = HYDRANTID (AVALANCHE CLOUD CORPORATION),
OU = HYDRANTID (AVALANCHE CLOUD CORPORATION),
CN = HYDRANTID (AVALANCHE CLOUD CORPORATION)

The serialNumber of “8987986-0143” is the registration number for “Avalanche Cloud Corporation” listed under the Utah Secretary of State – while the jurisdiction state (jurisdictionST) is listed as “Delaware”

This is a violation of the Code Sign Baseline Requirements section 7.1.4.2.4 which in turn references Section 9.2.4 (Subject Jurisdiction of Incorporation) and Section 9.2.5 (Registration Number)

  1. A timeline of the actions your CA took in response. A timeline is a date-and-time-stamped sequence of all relevant events. This may include events before the incident was reported, such as when a particular requirement became applicable, or a document changed, or a bug was introduced, or an audit was done.

2022-10-18 12:14 MST: Issued the EV Code Certificate
2022-10-18 15:41 MST: Discovered and reported the discrepancy to internal compliance team
2022-10-19 08:15 MST: Updated the details for the HydrantID organization DB record.
2022-10-19 13:00 MST: Updated the Registration EV Validation process to prevent a recurrence.
2022-10-19 10:39 MST: Replaced/Revoked the EV Code Signing certificate.

  1. Whether your CA has stopped, or has not yet stopped, issuing certificates with the problem. A statement that you have will be considered a pledge to the community; a statement that you have not requires an explanation.

Yes

  1. A summary of the problematic certificates. For each problem: number of certs, and the date the first and last certs with that problem were issued.

One certificate, issued on 10/18/2022

  1. The complete certificate data for the problematic certificates. The recommended way to provide this is to ensure each certificate is logged to CT and then list the fingerprints or crt.sh IDs, either in the report or as an attached spreadsheet, with one list per distinct problem.

https://crt.sh/?id=7785181702

  1. Explanation about how and why the mistakes were made or bugs introduced, and how they avoided detection until now.

The organization re-verification completed on 2021-11-11 failed to update the registration number from Utah (8987986-0143), to the registration number for the jurisdiction state of Delaware (4947261). This was not identified prior to this mis-issuance due to no other certificates being vetted and issued between 2021-11-11 and this request.

  1. List of steps your CA is taking to resolve the situation and ensure such issuance will not be repeated in the future, accompanied with a timeline of when your CA expects to accomplish these things.

Full EV verification has been completed at a minimum of every 398 days, in line with the CA/B F. Baseline Requirements for EV Certificates. Going forward:

  1. Existing validation documentation, up to 398 days in age and used for the most recent validation, will be reviewed for accuracy.
  2. Documentation will be compared to system data and confirmed to match what will be in the certificate.
  3. Updates will be made to the system data if applicable.
  4. Additional documentation will be obtained if applicable.

Thanks for reporting this. How does the community want to resolve this issue?

Assignee: bwilson → roots
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Summary: IdenTrust: Mis-Issued EV Code Signing Certificate → IdenTrust: Mis-Issued EV Code Signing Certificate

(In reply to Ben Wilson from comment #1)

Thanks for reporting this. How does the community want to resolve this issue?

Hi Ben,
Given that the certificate in question does not contain an EKU that puts it in scope of Mozilla policy, I don't believe that an incident report is required.

Thanks,
Corey

Ben, Can this be closed?

Flags: needinfo?(bwilson)

Yes - I'll close this.
Thanks,
Ben

Status: ASSIGNED → RESOLVED
Closed: 3 years ago
Flags: needinfo?(bwilson)
Resolution: --- → FIXED
Product: NSS → CA Program
Whiteboard: [ca-compliance] [uncategorized]
You need to log in before you can comment on or make changes to this bug.