Closed Bug 1802916 Opened 2 years ago Closed 1 year ago

Entrust: EV TLS Certificate incorrect jurisdiction

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: bruce.morton, Assigned: bruce.morton)

Details

(Whiteboard: [ca-compliance] [ev-misissuance])

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36

Steps to reproduce:

  1. How your CA first became aware of the problem (e.g. via a problem report submitted to your Problem Reporting Mechanism, a discussion in mozilla.dev.security.policy, a Bugzilla bug, or internal self-audit), and the time and date.

Entrust became aware of the problem with VMC certificates on 10 November 2022. It was assumed the problem was isolated to VMC, but more investigation found the problem was related to certificates which include ST jurisdiction information found through EV verification.

  1. A timeline of the actions your CA took in response. A timeline is a date-and-time-stamped sequence of all relevant events. This may include events before the incident was reported, such as when a particular requirement became applicable, or a document changed, or a bug was introduced, or an audit was done.
  • 2022-11-10 14:08 UTC - VMC issued discovered
  • 2022-11-14 9:05 UTC - Discovered the issue impacts certificates issued with EV verification; investigation started to determine which accounts were impacted by the errors
  • 2022-11-17 12:30 UTC - Compliance meeting to review investigation
  • 2022-11-18 15:30 UTC - Update search criteria with PM/Development and discuss problem resolution
  • 2022-11-23 12:30 UTC - Compliance meeting to discuss state/province issues in some countries
  • 2022-11-23 14:30 UTC - Compliance meeting to review incident investigation status
  • 2022-11-28 13:05 UTC - 322 EV certificate were found which were miss-issued with the incorrect jurisdiction
  1. Whether your CA has stopped, or has not yet stopped, issuing certificates with the problem. A statement that you have will be considered a pledge to the community; a statement that you have not requires an explanation.

Entrust did not stopped issuance; however, all issues discovered through investigation have been corrected.

  1. A summary of the problematic certificates. For each problem: number of certs, and the date the first and last certs with that problem were issued.

The impacted certificates is listed in item 5.

  1. The complete certificate data for the problematic certificates.

The following EV certificates have been identified as miss-issued:
https://crt.sh/?q=03E0C13C0E7714798D8F637F4BF48AEA062F460C
https://crt.sh/?q=00FFFF23EE35506E1CFA84E3EB2E435D5559E757
https://crt.sh/?q=77E973E11A11AADACA98153361A36E48067B17E5
https://crt.sh/?q=C084E58B37817F439164DFD31FE9EA67FF7CCAE9
https://crt.sh/?q=7B6E5F49B9CDCD7F70290F3FC8857E749BE44DDE
https://crt.sh/?q=A946177AA26A9A04AA22526872AB9E308829FE6A
https://crt.sh/?q=F0939F1F3935131DDFCE09D52CF12DFF429C5BD2
https://crt.sh/?q=7149797FF35B0FE53FD49D4620D1EF7DD48A7FF0
https://crt.sh/?q=78C1E9DF96509A84D6AB92B579EE8D4D9DE9FD9D
https://crt.sh/?q=FA8C876D6D10D38EF2E6BB02D8861A2EA49D794F
https://crt.sh/?q=EDACE2222B7EDC69FEA3321E3A9858DEDE609BDB
https://crt.sh/?q=E2D2A310768E4C16236FAC640E5D37531AD74679
https://crt.sh/?q=FC3333CE103042645FF51DEF08F2A1F5C5E0CAC4
https://crt.sh/?q=01D31BD53309DD4A603A79A8970410F122E30D7C
https://crt.sh/?q=80AD2DA6B4F8DDCA40735C2E6662155C2E9625EC
https://crt.sh/?q=CE8E4B603109F29177649E72C56DF6792A4263F1
https://crt.sh/?q=E6ABA85018FB0FFABBD5AF5821BF0BCB78AE15F1
https://crt.sh/?q=851447E27B97865AB55E5A7D9C0414E2256391C0
https://crt.sh/?q=F53E2F3266C6D74089D2F30703EAA8C5AEB788ED
https://crt.sh/?q=F436D5D630006C81BF1DB4D314F5286E3DC78131
https://crt.sh/?q=879ACCB19D818F815D1EFF593DCC98339BA48861
https://crt.sh/?q=4DDEDB7741E3CAA2416EE65FF8B7C2C86890DFB2
https://crt.sh/?q=B7EF273F99B8AD39B59CEB3582F432D465EED228
https://crt.sh/?q=738F0BA97E47F108096D87883845AEFC7F94C531
https://crt.sh/?q=8C11D8DCC5A85B1D3A5C6D52DA3DFAB5D9F31F51
https://crt.sh/?q=14DF09CF8D7F74556AB001B5ECFE425AEB284727
https://crt.sh/?q=DE2D01751BB9DA73862041D58DFC79A7A1E80D1D
https://crt.sh/?q=01B9F67250F492B9436109B0A40F483EC62E3F06
https://crt.sh/?q=6B04C33C7B4BDBFE3CB11E033050FB0FFB473CD6
https://crt.sh/?q=047A0E093991EAA89A8B901FA4B8D0CB2C80BF52
https://crt.sh/?q=C871E33FD0AA648CE854235A7BB0CCA338B12233
https://crt.sh/?q=F5539782A91A563AC1AB3B02EE5AD462EBD9F3D2
https://crt.sh/?q=97AC7A444C52131841D570AB6D28F385EB70E524
https://crt.sh/?q=460658C028C71ABD6BB01BB7FFEE52E81A088E5F
https://crt.sh/?q=AF04B38C849E8175F402BFDBDCD463D6F0AD7AEC
https://crt.sh/?q=C37AEFC09CC113E7C03FA9A9D8328BF9CBF72D4C
https://crt.sh/?q=8209273812D39AE8F8FACFE9023C003D4AC9D2D5
https://crt.sh/?q=6C07AE9673C675D64595607C306730F8EDBBBAE5
https://crt.sh/?q=51AA06A85C36B9863ECBF90850442CAD94F088F8
https://crt.sh/?q=18B9D71B00B5479FFDFF259680CCAA15E77E6FD3
https://crt.sh/?q=FD3C04643E416BD0D70254333BE44B4FB4085CB1
https://crt.sh/?q=4723A4922AE1A9FE66F8F9EE1C2931D8FF38493B
https://crt.sh/?q=7E87AEEADA7C9BD95C49296A7B56F4F9FF02CA6D
https://crt.sh/?q=A613E1476D10117AC0881A2091869C70171BA908
https://crt.sh/?q=269D12D175D125ACF926A7E1673B4A84652DB8B4
https://crt.sh/?q=811815C91A110FF9BED174A324C7EFD782E12F0F
https://crt.sh/?q=9693949646CC57F5C28C7DA572A8772FAEC152D4
https://crt.sh/?q=56F523397FD87C8E7BB8BCA649DEBA0EB503423F
https://crt.sh/?q=B29070A1D6A3323E090F51F971C59B1DC44974E4
https://crt.sh/?q=40DD035396AC735106E451287F9A5154237D92FC
https://crt.sh/?q=CE5AB17808741C7650C4D6C46443A52A366CE98B
https://crt.sh/?q=DBBA90C2B35D8C188E8744D2EAED329E163E96A0
https://crt.sh/?q=DE703DAD57EB51AF1C23D5307315D8530FBB2CD4
https://crt.sh/?q=ED77E3277CFAC87382AA583581C7D180ADA1F75F
https://crt.sh/?q=1334A4127C7FED963CBA6A9C227DA532B99DAA2D
https://crt.sh/?q=81EFFDA4F957C3AB5479FAACCBF01539C26F505C
https://crt.sh/?q=163AF1C707FC8E34EB39FEF251C3CCACB0866453
https://crt.sh/?q=7D365720B1E7BDEE248C49EA3AC2E21DB404E749
https://crt.sh/?q=8C2092F9CB4CED61F6F9AB2713EC52E2305D85ED
https://crt.sh/?q=48B6A7FB6D1523EED57AE9D5A509BA50E83F3EC8
https://crt.sh/?q=8D74B15A41DD5B731973CBF7C9B83811D9BE2741
https://crt.sh/?q=3FEBE0264366AF1B4521321EB2477835B28AD0FC
https://crt.sh/?q=401FE35FA7D7D044E574FFC2041B4231A93605F9
https://crt.sh/?q=E966E040DFCCC34D576F5D706B26737829B733D0
https://crt.sh/?q=50269B55AB495E63B1FD5D9273D7B4330F066CE7
https://crt.sh/?q=D75A10CD847C6646978105DF88A6E6EB5966A6E3
https://crt.sh/?q=1418F73F36C691CB36BF16573742425247E592BB
https://crt.sh/?q=4B42BB26AE17979EDB2B8ECD9C7EAA2F34E2ADD8
https://crt.sh/?q=FFCA67F796E7B8775701625BAF6B00F72FF06390
https://crt.sh/?q=B7629A75D00BC96A8E819A33AED9E369F60977D0
https://crt.sh/?q=6B5AA671822CC4D4348248FA4CF831CD6F58AEE9
https://crt.sh/?q=64C23B3296EF4F7B96283D0D426AA68E2DFFEC4F
https://crt.sh/?q=63203C9734279FBFBF48DC63394BFF0C1DB22FC6
https://crt.sh/?q=E1AF366C7B0DA5655A255B410B0D9AB9A39401DB
https://crt.sh/?q=7BE9041AB0B5E724DBF2645938202C12F8B81F25
https://crt.sh/?q=F8DDCE5FF671B9400867D18AC86406260A7F0267
https://crt.sh/?q=F5FB265860FC36BF7E54274037B1868C7F86F5C3
https://crt.sh/?q=C28F0346E555073C050F4869CD975DCF65E67C23
https://crt.sh/?q=3C11A8881BBC7B7EADD17355C038FCEBC7C84378
https://crt.sh/?q=1D39BA9C2534FBA82874C4F932EF2BE8797295C3
https://crt.sh/?q=39AF13F41D6A894CB008058EF7537B6F6C80E098
https://crt.sh/?q=9AC2AAA2590D81223BEE0A16D6352202C635279F
https://crt.sh/?q=8916EFD8A03FAA5A8F2E56F68211E2AF6BF554F6
https://crt.sh/?q=8E8AD1EDFF8034F7655918639BD6B80B0F6E6A20
https://crt.sh/?q=D727A3D99E2E9F8E2577C8BC507A3E226B356660
https://crt.sh/?q=63C8705D223A8DC1AB86E8B7E3576DE7CC329A20
https://crt.sh/?q=6A9325EF973AD5EC5B3FB9C0F4E35ACEF1F5D1C8
https://crt.sh/?q=0E6B4F12CF2A067007EF517F3DD0B6DDFCBF8EF7
https://crt.sh/?q=FF96898C01EE9CF770E4DF2924B4777C3E1BABC1
https://crt.sh/?q=F10FF2366B01465802DEBF36A6B9236149643EA9
https://crt.sh/?q=DFBF3C2AE3FC1F4DDCDEDB5A2BF42006A778823B
https://crt.sh/?q=820ACA7E0AF12261E9CFE399B7A7EF27B352173C
https://crt.sh/?q=8646F06475EFA391D80BAB4AE0C3CF43F8088AEF
https://crt.sh/?q=3511A4E37BAEBF061E65DD21CE73F3788BD629B0
https://crt.sh/?q=5EDDB3A8C4A6BC5A41A1FEE98FFC7968CD62A3DF
https://crt.sh/?q=41B4C88E6C5BCECE10B6CA3FF99E324FA4F3FAFB
https://crt.sh/?q=5550144DCB39CBB3DBA9CB3174575068ADDC7BDB
https://crt.sh/?q=6D09E8AC373DB48AA684BF7818C91B30ADA8A17B
https://crt.sh/?q=CE6A76476DE885DA1521BAA41B1A7622BA901837
https://crt.sh/?q=28EA0EF3DA7471521B9E0A0BD3CD361774B2E173
https://crt.sh/?q=9089FE417152CE6B8B12D0101008D51BB19B269E
https://crt.sh/?q=785AC4D12D97E79E7BEA9C432CFD941B94A733BB
https://crt.sh/?q=935A1B22DE8D68F3F353CD75AFA233F1AC913FBB
https://crt.sh/?q=E0FD9D2BFC8167AD28EE1F2A9E2BC7D55CC5D2E8
https://crt.sh/?q=56DC0BC59EF65A26BE827196D4BEC7B697C94D28
https://crt.sh/?q=1E66C75ED2CCCF9718C82660EE2D04482264023B
https://crt.sh/?q=F5C3BB285AC5D2C929E476480B5B3AEC6AAA51A9
https://crt.sh/?q=E979DE5E80CD80F904EA0C8645ECCC1AEBBC2B92
https://crt.sh/?q=AE55F26286CA8A90A7809EA44F3AC28A1E3179D3
https://crt.sh/?q=679693A0CE5FD9211B2A47A77E34F35FDA92BDE7
https://crt.sh/?q=DB17C4A9BF10F6D6C2AE5F6546677932177ED264
https://crt.sh/?q=24048BDD3F49A30CC4B7D93917B202E2403F2851
https://crt.sh/?q=241670E5161DE771B3800605584139B12DF1A5D6
https://crt.sh/?q=B92BF0B6C9662220573BBE6C4865567B097FBA4E
https://crt.sh/?q=8464B340984F37309E9DE7F0BB8B075A23FF7DC0
https://crt.sh/?q=7DA34C20239B02FBE30A4DF5968103EEC4CFB618
https://crt.sh/?q=6AAC7B939499044BD9C123C251884E79CC53B899
https://crt.sh/?q=7D740780CA87D21ABB579D14B8599A2D39B4504F
https://crt.sh/?q=95D557930E65BA453169195A6E4F1EADD2CF9F25
https://crt.sh/?q=029E342255AB7B3A7662B554417083476F4ED6BC
https://crt.sh/?q=5702ADD01C4898ADD1E3CB28F7D003AD13A4DE62
https://crt.sh/?q=3BD3470C610EE0283EFA7E7145AC4601FBD72223
https://crt.sh/?q=DE8B5CBE91D5D3D41B5853213DF226BC3C6638CE
https://crt.sh/?q=8FF8285CA5998BE5151F97668DD847D45E49D311
https://crt.sh/?q=9824D2A4B852D68BC71E0280D3A453EF6D59A37C
https://crt.sh/?q=EB6F1D67F9DE44ACB8497FE92FD824914742DF1E
https://crt.sh/?q=6A4A90D4F4EFEB124EBD9F384B2FA2E539CDC76E
https://crt.sh/?q=58C2EF3CD31A68F3635DAD7DC4478B01300D94E3
https://crt.sh/?q=6090E53D69B670BC6555C1F7EAF74DE3392AA683
https://crt.sh/?q=B780B5C6B2E49A7AD0916764B8C44C661B009C8D
https://crt.sh/?q=8EC33157E190B5C33F3583E7318C9B9C28986CB9
https://crt.sh/?q=521FFD2201DF211945CE97E078F3CE8C0C4E0CA6
https://crt.sh/?q=BF6DAC1DF6B3575724B6F7AD37D70E2B6CAF6891
https://crt.sh/?q=E55E1CF06807A06878AFF954B7EF9C5AE23BECAE
https://crt.sh/?q=D0063737A4E6B95E76ABF5A7CFA13579152B36D7
https://crt.sh/?q=C4EA25CB622610E8DC5E8D6C5B6B094A0B43B4F5
https://crt.sh/?q=8D58C2940E3A1A11D7BDD7A38D7D878981200CAC
https://crt.sh/?q=C21ACDA199A7C806873E0BDD581D010AD6EC0D1C
https://crt.sh/?q=9EA0B4D6BAF678AFB84530E14246272BBF776BAB
https://crt.sh/?q=73D2619ED63FD375FD95B627886AD7EA91607475
https://crt.sh/?q=5FA16512579372DE771028DDDEAD7EC4EDB37D19
https://crt.sh/?q=0C2604E5AC6ABE8D1F0DF8DCE32DFFB75D8E3A5C
https://crt.sh/?q=1E6F76AFC9613B3B00B26C152F07F5B02B02DAFB
https://crt.sh/?q=48B132BB2BDB70B09A7102899BCF36DC2D3EE0EA
https://crt.sh/?q=582634102B8A9F45754C560271AD3D2BB6FF56EC
https://crt.sh/?q=47E095D775173D6E5119B80FC8D21B4663D0B673
https://crt.sh/?q=E5B318482905BBD3AFFDAE080148D3E9E19D184C
https://crt.sh/?q=A8A4A8B1405A1B51B1F3DD15A342032E0C213E1D
https://crt.sh/?q=255766382E627AC91E2802BFD9BB716402796A66
https://crt.sh/?q=EF4F3441A7D783AD00C25C85CCF4ECA48CB8C140
https://crt.sh/?q=932F8BC346031891A2D38755A68A7D7D1F05696A
https://crt.sh/?q=DE832B4A31A1F1DEBFD58EEB8D1C65145FDF2762
https://crt.sh/?q=54C760566031B7F708CA0617E316F87B87F975B0
https://crt.sh/?q=9A4C8E3DA5FC5FE9A75CD92A1FC93FEB71B440CF
https://crt.sh/?q=413A3A1622E6522F619D7D3AAC9C6074A70AA678
https://crt.sh/?q=CFBAD3E9AD720C628F67A0A3912CA279E3D5D02B
https://crt.sh/?q=52C242E014D6D89839341F6A5A0422F000E32A4C
https://crt.sh/?q=5B6A22871F950AA05101A7CA3AFFF9B9F7DE6C45
https://crt.sh/?q=9DEFF007DBA7B12BA2FAC8CC846C47013B9F8803
https://crt.sh/?q=5CE613479F66D76CFB9B89464FB6B804023CCA81
https://crt.sh/?q=83BF2AE57E604A531C67B45FBDEF05028D63D706
https://crt.sh/?q=A9DC8BCE26B259DB75122A566E0F642701CC24B5
https://crt.sh/?q=108298F5B522B2342BF11939E07E98DBF9223C92
https://crt.sh/?q=902CE6A8ED6CB4B43632E192D367F19F56D91908
https://crt.sh/?q=8F5E66B915B99EAFFDB5D27CDF877698CBBDADAA
https://crt.sh/?q=99AD4FD2A4D2AF2ABF182C9DD83B57E31A4B721E
https://crt.sh/?q=8785C560F8F6C5A06A55D8617419C4AA1A16F335
https://crt.sh/?q=15424AF5062D6E734456041E65C8C09F8357D177
https://crt.sh/?q=DBBB965B48329CE4F5DFDC33A5B1EC7046BE95FD
https://crt.sh/?q=DAAF271D72593570925D59EEDFB27168066D2725
https://crt.sh/?q=0C9993B55A2AD02D8ED1ED4EF1074025EFB1BBC0
https://crt.sh/?q=9DA2010E3BEA32A49BD9DB6BC0F6185384E57976
https://crt.sh/?q=14B8DA7A8C1A3833574777C6E08EE6FA7A46E3EF
https://crt.sh/?q=702ED008E6456C7F4D6F49F08478E149151D821F
https://crt.sh/?q=9312E085F130E629E32C3C1A9ABC74084ECA887B
https://crt.sh/?q=FD94F509AFF6DE80BA013C353DACF9E53195D0E9
https://crt.sh/?q=CDF40BF065FC90E8DFC5BECC6D084D5FAF7EFBE3
https://crt.sh/?q=FBEFE9EEF9316C02EB2F9DD7B0A7DADB666C2A4D
https://crt.sh/?q=C63442A268585EA552A77624DC233F49FD065783
https://crt.sh/?q=CCD80549D2CF0631B5F6DCA2674F2F5193B06B52
https://crt.sh/?q=E3499AFDF6800EAAD0B7D7ABB4217D26C2554AFE
https://crt.sh/?q=09F46BC67E7A974E9E6EC61828B7716374C12E96
https://crt.sh/?q=20A48DC98E601A55C0F37442A78BC6EB53D70535
https://crt.sh/?q=000358A152CA9049ED6C31B676468B73B3C962B1
https://crt.sh/?q=2DF3BE8F0BE83323B977DEF2E7C7A10EEF6C4E84
https://crt.sh/?q=149D40602755CDE8A8FCD30507A85D6B751BEDD8
https://crt.sh/?q=BD41CDA918E7A31CFFBFEFE93D4E7B68D3ECF292
https://crt.sh/?q=F855DB8B59760E3486CF6BC68745BE5244155D83
https://crt.sh/?q=5D1B8E3196B69CB6D129277CF2368820D35E2E04
https://crt.sh/?q=24E63D8E66F176344D02E9396BA50E058E93C6BF
https://crt.sh/?q=EE0E750D5A00787099856E2A4012460E1C9B5EDE
https://crt.sh/?q=23C0E78914A1AA794BFEA2A8C6D09FE83E1D349B
https://crt.sh/?q=DDB74CBB3E4185785835FBF9B49AB6AFD4B1C766
https://crt.sh/?q=A8628E8AE11126EB35BA66DA8B618FCDBC142DB1
https://crt.sh/?q=63F7C2AE77DDDA9C99298A330E25A7CEA7EE8066
https://crt.sh/?q=45554657D31029C0E3C56CCEB84F69A64CD891D9
https://crt.sh/?q=8D46FF671E50AE5BF93E863F99E6C6F48ED1919F
https://crt.sh/?q=9B11C63E7EBA7887D009A5E8AAA7277C11A8E1F3
https://crt.sh/?q=85823600AC93431FBF5F3547D13238BEBAF3CB48
https://crt.sh/?q=43ED457E56CEF8FCD3AAB876EBCC583E72C1E681
https://crt.sh/?q=536F43D7A4487EBE3808EC8123A1D0915A627525
https://crt.sh/?q=465E0803439297D7C065159784D02685CD4196D8
https://crt.sh/?q=54C7537ED54C69C0FDF4F14C9F463B3D0DCD2CF0
https://crt.sh/?q=BE490AC0BD290121A89B1F959CEF2F6D520DA8E0
https://crt.sh/?q=5D118139A14B958D8FFB26D6B050BCD34D8C983E
https://crt.sh/?q=FB3B50F130311444D26112C27DB2CFDF88C4C4DC
https://crt.sh/?q=0AEA7E795B7F6E2364FE48B02251879FEC478920
https://crt.sh/?q=73CC24B5ADC0B05471BCFF3A603561DEF638D30B
https://crt.sh/?q=744AC099237F4CEB2B701703BB2C56ADB400515A
https://crt.sh/?q=C0D48618D0FAF6EDCFB82C6441D5BE792C5DE658
https://crt.sh/?q=BC81D58DD674428A9D15540D3939726AA659B917
https://crt.sh/?q=C4D0D29470E2237771E27EAC6596860782CE77AB
https://crt.sh/?q=AB432F411B97CBCB0FC9B08E53205CF882BE2D2E
https://crt.sh/?q=953235E73F657E00ED0FEF670E14E26E85490DB9
https://crt.sh/?q=1B4EC336C6665F3AB56098F4835FF0D7A876845E
https://crt.sh/?q=F21FA8740673B05CC5A0DF28C1A3AF45436B7FB5
https://crt.sh/?q=04F367DE904B4A17C4DB01C69DFA8D251E404ADD
https://crt.sh/?q=48C64516B63187EB196514A4E28C99DD3EC5B7E2
https://crt.sh/?q=3F4A138EC27E2017D3289E1DB378164B91AEF755
https://crt.sh/?q=FC3AC54275E19238B027B32C4125C8D28E6CEACA
https://crt.sh/?q=BC6C25426550D850D6DC699BCA43E0481BB7B7C9
https://crt.sh/?q=BA9627717E0CD28EB993F98367F3014915CC6BE4
https://crt.sh/?q=B7B4E845B116BC5226C8D498CC1AB91CDE181925
https://crt.sh/?q=3E1EB15C7523CDF9B8E28D97F04FC270454CF403
https://crt.sh/?q=B9FBD685D5708688A45ACB8B326F72FA3848CB2E
https://crt.sh/?q=59EAE3BBB3BB1E9A645048CA28C35F2ECBDC2FE1
https://crt.sh/?q=161D990C16F6EDB8453439D46FA65BBBCB855D6B
https://crt.sh/?q=73980E904BC812E5E89C878F41FF5BB9C4A2726F
https://crt.sh/?q=3CD1653B21C1B40C752417803BBCB81ECFE24C67
https://crt.sh/?q=E7E094DD9E96CFADD874FF09A0F622A291615BE2
https://crt.sh/?q=2E8A6B3E6DCC38446A0CAA0E6247C1D1EB1B8400
https://crt.sh/?q=9E3D3EA2006446AB2011FEBB5CEE3578A7DC9667
https://crt.sh/?q=EA344AEDFB303B75BD9C2C6E44221556E8CADF62
https://crt.sh/?q=CDA21ED59A1D2F349DEC860D15E18C61C31F788A
https://crt.sh/?q=585489B1A4F3214EBD9D12E617CF776898E5B090
https://crt.sh/?q=51B8D4CDAAED31495611AC44C48AB979538E5426
https://crt.sh/?q=07F0D5AB50D65ADC94E9918A202A18A7141D9080
https://crt.sh/?q=7ECCAE9FE3B654D864069345C4726BA43434D665
https://crt.sh/?q=DF485FF55F545D0A07A9B5831F7B2B819896A996
https://crt.sh/?q=2FC9AB2429ECDF3793DF652541B6C7DCDA9F8E59
https://crt.sh/?q=9632FF1441C7DA324069BF8B6D91961CA0DA1147
https://crt.sh/?q=A1B4D3F668C5FB31F64FD5FC505CA2E4A82C8BCB
https://crt.sh/?q=8BC4D16A302515C1D4528466E678AB242A7BF802
https://crt.sh/?q=14D888F7F2C109617485747A1609DE8B0096A2D1
https://crt.sh/?q=85D0AA853374A109DE68E0E0BE3AE8B8BDF99535
https://crt.sh/?q=1499864D4969EE6C4935B46EC67B4E1934F2A17B
https://crt.sh/?q=251C0E350830A51D681464324674B28579432C09
https://crt.sh/?q=8603287B09EDB93B0CDE970D84710801512CD630
https://crt.sh/?q=455975CE2AED870A316AC1A90BFC37303D762F02
https://crt.sh/?q=2D2EDC0D5E0A89FCB5233EC7A502B34324CB41DB
https://crt.sh/?q=3CC23ACD29C8A59E1770A2204F28F0275DCC8819
https://crt.sh/?q=8D8E5C447CAF516A486501C5A683BE6D7CE03416
https://crt.sh/?q=392E11CC76158DC8023C18EA2F3B01DDD21A5133
https://crt.sh/?q=213426840D63949E2BA0F3AE7DBCF3EE67BC6BD6
https://crt.sh/?q=4499A5969E50A4C7682D7BB5B82318D71BF4ABC0
https://crt.sh/?q=69B8BFB8B6FB472EE9F1089BABC087D503401E9D
https://crt.sh/?q=2079DC4425B1E6AFFF42FD9E25DCF4069D230D97
https://crt.sh/?q=F48EC2C8B1E0D73FBA219540491963F47CB213BD
https://crt.sh/?q=0250793426275D5DE98D7B1427C7C348C01CDD5A
https://crt.sh/?q=F48FB493DAD35E89F6C4D4A18A29B55033AB3BEA
https://crt.sh/?q=47669B68D36438E59A958F95D721845B7F738E85
https://crt.sh/?q=5F549278FEBFE72C585883466D18D688CEB5EE90
https://crt.sh/?q=03F5CE2A89A21CC011816A14061B7ABB1D014D68
https://crt.sh/?q=4D63A1C121786D23134660D9F87C38EB67F525F4
https://crt.sh/?q=EBC8D6A6ED6AAAC6C0AE3F49A07EDBE379370288
https://crt.sh/?q=A029225F5395B0F71238E8A6D875C1E70F357C3B
https://crt.sh/?q=6D9B6D82E6D5779F0D6C9D2D659B89FB1DF6314E
https://crt.sh/?q=1CC1495D18A9901439E6F2F3E8C5420FC2169F26
https://crt.sh/?q=CBAE568383C282643A580D244EED9E7E0E5C18B7
https://crt.sh/?q=F610EF34FBACA773AFDB6ADD98213D3D8C3280B8
https://crt.sh/?q=FA3E8ED8CEE13D6A5C39E8B310FFEA439C260D85
https://crt.sh/?q=D918E7B4C667B191C9BBCAF5FD75FE82F93ACD6E
https://crt.sh/?q=D8C72DAC0DF3BA15576628986F5342321D51DE87
https://crt.sh/?q=7BA428DBFF86F8F2DD24F80AA58B327A47F2C30E
https://crt.sh/?q=ADACEE90E65DB5E505D10C9336B3311B30DDDBF9
https://crt.sh/?q=814F31CA460710C12F891343B9414C9122F1E759
https://crt.sh/?q=51A4EE8025D0D9D2BE8AEC16066DC8A28C6F85D5
https://crt.sh/?q=697E7367263687E694EA35E88DF8AAFFF26C37AD
https://crt.sh/?q=D5BD7BB99745D21F79AC7C7AF98395ADF17002ED
https://crt.sh/?q=8A083BFDECE78F7259D2ABC5F5A7136AF3F1D48B
https://crt.sh/?q=BFFE1F4F0C7C091885AA270DAFF9C6C5317530C3
https://crt.sh/?q=3C1A2E1B0633A916A5E9E47F5C7319C03A8F75E8
https://crt.sh/?q=CA87080AE337FA79F798C69EA48691EF61FDE810
https://crt.sh/?q=62C370628230411746C30F9F257EC94636E40584
https://crt.sh/?q=D0BA6F104754EC728213764C39396CD0EFF98FE9
https://crt.sh/?q=13E9EF3403807CB50EA5426DB34D020605E02F91
https://crt.sh/?q=DB3726163A2C0886DB7D76D56C3D7B5645D21BCC
https://crt.sh/?q=194509E60AC42501F938E8902B000B069BE07748
https://crt.sh/?q=C0F44B265036761850A79E08E73F6DC6D3995D6C
https://crt.sh/?q=7CDAB97E7D94A293CB4DFD5E0A92B3F9E463BC8E
https://crt.sh/?q=685D9E4DD8F2F05B4EF9714348CA8101487CC43D
https://crt.sh/?q=438B4F85F340C284CD9F60F25CBF8945887D4CC3
https://crt.sh/?q=F76B969CBFD78E71561F6D49CA4C78132322BCA5
https://crt.sh/?q=C9A0EDD88C5DFA3800311481C2F2F0CA54757CDF
https://crt.sh/?q=BAEE9250E7314B72BC8F869948E4EC6B6DB2D3DF
https://crt.sh/?q=36E78ECFA59B7D7FFA85E6F72F27C79003F7787A
https://crt.sh/?q=BA557CCA7DED8DDE6C03011FC168F073904C6EB5
https://crt.sh/?q=9E197E3D7D903C00BB8CB044BD0AF7F6045989AF
https://crt.sh/?q=11377DC7D660ACCBA7866B559D1FA97AE480C796
https://crt.sh/?q=7C8F920E66C775D97DF076957B458BB720F69E3E
https://crt.sh/?q=FD5E55A3FE9E0A57FF50C4D556DDD3762C13794A
https://crt.sh/?q=F425A4985BE3F95D96535E4ADDB86D843BA2EB77
https://crt.sh/?q=A6F112D4AB4E0DED5FAE4E3E2B3F606E545ECAA1
https://crt.sh/?q=C961C7B91BD31213235DACFB39803387888F4CC4
https://crt.sh/?q=44689749A453AB16D740A2551CEED66B3A71DB9D
https://crt.sh/?q=94AC77C69FD4CB39DBC5B399E18D1848884079AB
https://crt.sh/?q=36E1FE12CF98EC9D75E134E725A87C0933894129
https://crt.sh/?q=DB93E493B3D70FB083106224B2BB283AD93A69E2
https://crt.sh/?q=2762127A49CFB1E58A293C1A27AEE3C834673D24
https://crt.sh/?q=363D10788FC8C88A712D726C047E79E0DC34A0EB
https://crt.sh/?q=BD38DDF30EB8C044AFEE81D1A3716EB5FF9BF0A4
https://crt.sh/?q=02CF2385ECD9551E0B04C374A21FA75871218D76
https://crt.sh/?q=B107FBAD293074CFCEDF48F58B37E76652024A85
https://crt.sh/?q=498E8A5E80624BA7B959076F8CC7F00FB7208013
https://crt.sh/?q=E2B4BF9569E93B4CA7F7DED8CB2FA5E4AF6AD983
https://crt.sh/?q=9C7DAB77516A05F42DE469C173D4373081347521
https://crt.sh/?q=C7BDC332C9BB8D3D47E331379993B579B669FBF4
https://crt.sh/?q=158C54EB2920963265D4D72C2A89F478F8F316F0
https://crt.sh/?q=2BF17C0277696D19BD28ABFA8B409074145B0B27
https://crt.sh/?q=ECC3A5309EE1C7A5354BD2C182A662B3943C385B
https://crt.sh/?q=67F5A33F5BF5EF723BFAD81111F06C75AF7C7237
https://crt.sh/?id=7532054567

  1. Explanation about how and why the mistakes were made or bugs introduced, and how they avoided detection until now.

The problem was detected during revalidation of a VMC certificate.

The errors occur when the data is input by the Verification Specialist. The errors were:

  • place of business ST field was incorrectly used in the ST jurisdiction field
  • place of business ST field was incorrectly used in the L jurisdiction
  • ST jurisdiction was used, when the registry was from the country level

The errors avoided detection as the pre-issuance and post-issuance linting software does not address the contents of the jurisdiction data.

  1. List of steps your CA is taking to resolve the situation and ensure such issuance will not be repeated in the future, accompanied with a timeline of when your CA expects to accomplish these things.

The new design will be to align the approved incorporating agencies database with the jurisdiction data fields. The system will be updated to ensure that the approved incorporating agencies provide the corresponding jurisdiction data. The design update will help to remove human error.

  1. A timeline of the actions your CA took in response. A timeline is a date-and-time-stamped sequence of all relevant events. This may include events before the incident was reported, such as when a particular requirement became applicable, or a document changed, or a bug was introduced, or an audit was done.

2022-11-10 14:08 UTC - VMC issued discovered

Could you explain what a VMC is, or link to a definition?

2022-11-14 9:05 UTC - Discovered the issue impacts certificates issued with EV verification; investigation started to determine which accounts were impacted by the errors
2022-11-17 12:30 UTC - Compliance meeting to review investigation
2022-11-18 15:30 UTC - Update search criteria with PM/Development and discuss problem resolution
2022-11-23 12:30 UTC - Compliance meeting to discuss state/province issues in some countries
2022-11-23 14:30 UTC - Compliance meeting to review incident investigation status
2022-11-28 13:05 UTC - 322 EV certificate were found which were miss-issued with the incorrect jurisdiction

Why did it take so long to discover the problematic EV certificates?

Did you start searching for EV certificates with this issue before 2022-11-28? If not, why? If yes, why did take until 2022-11-28 before you got results?

  1. List of steps your CA is taking to resolve the situation and ensure such issuance will not be repeated in the future, accompanied with a timeline of when your CA expects to accomplish these things.

The new design will be to align the approved incorporating agencies database with the jurisdiction data fields. The system will be updated to ensure that the approved incorporating agencies provide the corresponding jurisdiction data. The design update will help to remove human error.

Could you expand on this 'new design', and what is being newly designed?

Are you planning to revoke these problematic certificates, and if so, when will they be revoked?

Assignee: nobody → bruce.morton
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true

(In reply to Matthias from comment #1)

Could you explain what a VMC is, or link to a definition?
VMC is the Verified Mark Certificate. This certificate has EV verification and also includes a logo. You can find the VMC Guidelines and more information here, https://bimigroup.org/supporting-documents/.

Why did it take so long to discover the problematic EV certificates?
Did you start searching for EV certificates with this issue before 2022-11-28? If not, why? If yes, why did take until 2022-11-28 before you got results?
The jurisdiction information is very complicated. Some of the reasons is a single registry could be accessed by multiple sites. The multiple sites may be interpreted that the site is for a different jurisdiction. There are also issues where the state for place of business and the jurisdiction state might be different. So there was no easy search methodology to find miss-issued certificates. There was a lot of investigation to confirm if a certificate was miss-issued.

Could you expand on this 'new design', and what is being newly designed?
I will follow up with more design information on a future post.

Are you planning to revoke these problematic certificates, and if so, when will they be revoked?
Our plan is to revoke within the 5-day requirement; however, we are getting both disputes on the wrong jurisdiction and the timing due to the current end of year black-out period. If we have late revocations, we will open a late revocation incident report.

Through the planned 5-day revocation period 62 certificates were revoked.

There has been pushback from the Subscribers due to the critical use of EV TLS certificates, coordination with the technical teams and the current annual black-out period to reissue certificates.

We will open a delayed revocation incident report to address the delays and track revocations completion.

Incident was posted for late revocation, https://bugzilla.mozilla.org/show_bug.cgi?id=1804753

Regarding the new design. We will review our EV approved incorporating agencies matrix, https://www.entrust.com/legal-compliance/approved-incorporating-agencies, to ensure the correct jurisdiction is established.

To ensure the correct jurisdiction data is in the EV certificate, when a Verification Specialist verifies or re-verifies an Organization, they will follow this process: 1) Select businessCategory = Private Organization, 2) Choose the country, 3) Choose a registry from the dropdown for the country, 4) Verify the organization is in the registry and record data including the registration number. Note by selecting the registry, the jurisdiction location information is selected in an automated fashion, which mitigates human error in selecting this data.

The plan is to update this functionality by 31 March 2023.

As a follow up after the new jurisdiction functionality is in place, we will plan to use the registry matrix for post-issuance certificate linting. This will ensure the EV certificate jurisdiction data is in sync with our trusted source.

Whiteboard: [ca-compliance] [ev-misissuance]
Whiteboard: [ca-compliance] [ev-misissuance] → [ca-compliance] [ev-misissuance] Next update 3-Apr-2023

(In reply to Bruce Morton from comment #6)

To ensure the correct jurisdiction data is in the EV certificate, when a Verification Specialist verifies or re-verifies an Organization, they will follow this process: 1) Select businessCategory = Private Organization, 2) Choose the country, 3) Choose a registry from the dropdown for the country, 4) Verify the organization is in the registry and record data including the registration number. Note by selecting the registry, the jurisdiction location information is selected in an automated fashion, which mitigates human error in selecting this data.

The functionality was deployed on 14 March 2023.

Thanks. Unless there are other comments or concerns to be expressed, I will close this bug on next Wed. 19-Apr-2023.

Flags: needinfo?(bwilson)
Flags: needinfo?(bwilson)
Whiteboard: [ca-compliance] [ev-misissuance] Next update 3-Apr-2023 → [ca-compliance] [ev-misissuance]
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.