Closed Bug 1856591 Opened 2 years ago Closed 2 years ago

Telia: S/MIME certificates issued in violation of S/MIME BR v1.0.1

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: antti.backman, Assigned: antti.backman)

Details

(Whiteboard: [ca-compliance] [smime-misissuance] Next update at 23.2.2024)

This is initial report for missisuance of three (3) S/MIME certificates by Telia CA. Full disclosure and report shall be updated on this incident no later than the 10th of October 2023 16:00 EET.

In monthly compliance review at the 2nd of October 2023 for all issued S/MIME certificates by Telia CA in September 2023, Telia CA became aware that three (3) S/MIME certificates were issued at the 1st of September 2023 by technically constrained CA (CN=Ericsson NL Individual CA v4, O=Ericsson, C=SE) to Telefonaktiebolaget LM Ericsson AB personnel.

Identified certificates were found missing required Policy OID for S/MIME BR Sponsor validated Legacy (2.23.140.1.5.3.1) and required organizationIidentifier in Subject (attribute: 2.5.4.97) and thus violating S/MIME BR v1.0.1 requirements sections 7.1.6.1 and 7.1.4.2.2 (d) respectively.

Telia CA Administrator responsible for monthly compliance review informed Telia CA Security and Compliance manager in the early evening of the 2nd of October 17:42 EET of the incident.

Telia CA Security and Compliance manager initiated immediate review in the morning of the 3rd of October 08:01 EET to confirm and verify the said compliance issue to be factual.

Telia CA's weekly Security Board convened at the 3rd of October 09:15 EET to make final review of the incident and verify need for public incident reporting in accordance with S/MIME BR and Root program policy requirements. Telia CA Security and Compliance manager was designated responsible for public reporting and required internal resources were immediately assigned to collect the evidence for full disclosure report.

Immediate actions were initiated both internally and externally to inform affected persons and to collect details and chain of events to identify all the details why the certificates were in fact mississued.

Full compliance check for all issued S/MIME certificates before the 2nd of October 2023 was executed by Telia CA and other problematic certificates were not found.

Affected certificate holders were notified at the 2nd of October 15:00 EET that their respective certificates shall be revoked on Thursday the 4th of October by 17:00 EET. Telia CA determined that immediate revocation of certificates would cause undue harm for the affected persons, the delay would allow affected persons to obtain new certificate that would be issued in full compliance with the S/MIME BR.

List of certificates:

Certificate 1
Serial HEX: 01:8a:4f:3b:59:7d:77:27:86:21:49:09:a4:b9:5d
serial DEC: 7997546776479856255670047314590045
SHA256 fingerprint: 9D:EF:1B:B2:76:A3:E1:77:9C:8E:50:7D:64:EE:BF:2C:A4:18:C5:0F:60:FA:D3:4A:9F:16:BF:DF:81:7D:32:BF

Certificate 2
Serial HEX: 01:8a:4f:3b:d9:8d:a5:72:17:0e:63:0e:aa:51:e9
serial DEC: 7997546931298772953350938101961193
SHA256 fingerprint: 50:5F:8B:04:6A:FD:05:51:7E:A6:ED:DB:C0:E1:FC:FC:B5:6E:A3:6F:86:D5:FA:C0:1D:49:1C:C0:E3:C1:C7:66

Certificate 3
Serial HEX: 01:8a:4f:3c:1d:1d:3f:cb:cf:73:a9:b6:0e:36:91
serial DEC: 7997547012974948538197422564587153
SHA256 fingerprint: D8:03:FC:DB:AC:91:CA:96:98:ED:B3:D1:E9:ED:2E:FF:82:64:3C:D5:B8:37:7E:CC:48:AD:26:0B:5B:35:2E:87

Full disclosure report will be submitted no later than the 10th of October 2023 16:00 EET.

Assignee: nobody → antti.backman
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [smime-misissuance]

This is to update that the problematic certificates have now been revoked as informed in the initial incident report.

7997546931298772953350938101961193, revoked 2023-10-03 14:49:50 EET
7997546776479856255670047314590045, revoked 2023-10-05 16:40:02 EET
7997547012974948538197422564587153, revoked 2023-10-05 16:40:02 EET

Full report expected to be filed as planned by the 10th of October 16:00 EET

This is correction update to the previous update on revocation details. There was a user (mine) copy/paste error on the revocation timestamps for two of the problematic certificates.

Correct revocation information details for the following certificates is:

7997547012974948538197422564587153, revoked 2023-10-05 16:46:49
7997546776479856255670047314590045, revoked 2023-10-05 16:48:12

As previously reported, this is the full incident report of the issue, we will continue to monitor responses to this report and update periodically on the progress of listed action items:

1. How your CA first became aware of the problem

(e.g., via a problem report submitted to your Problem Reporting Mechanism, a discussion in the MDSP or CCADB public mailing list, a Bugzilla bug, or internal self-audit), and the time and date.

In monthly compliance review at the 2nd of October 2023 for all issued S/MIME certificates by Telia CA in September 2023, Telia CA became aware that three (3) S/MIME certificates were issued in violation of S/MIME BR v1.0.1 at the 1st of September 2023 by technically constrained CA (CN=Ericsson NL Individual CA v4, O=Ericsson, C=SE) to Telefonaktiebolaget LM Ericsson AB personnel.

Identified certificates were found missing required Policy OID for S/MIME BR Sponsor validated Legacy (2.23.140.1.5.3.1) and required organizationIidentifier in Subject (attribute: 2.5.4.97) and thus violating S/MIME BR v1.0.1 requirements sections 7.1.6.1 and 7.1.4.2.2 (d) respectively.

2. A timeline of the actions your CA took in response.

A timeline is a date-and-time-stamped sequence of all relevant events. This may include events before the incident was reported, such as when a requirement became applicable, a document changed, a bug was introduced, or an audit was performed.

2023-08-31 14:00 UTC

Telia CA Development Manager found out during performance of final readiness check for S/MIME BR compliance of CA applications and corresponding APIs that specific API for the issuing CA was not ready to be deployed in planned time late afternoon of the 31st of August.

2023-08-31 15:00 UTC

Telia CA Development Manager issued required development resources to finalize the API functionality to meet the S/MIME BR requirements. At this point when planning with the development team, it was evident that functionality could not be deployed in time.

2023-08-31 17:10 UTC

Telia CA Development Manager made decision that the required software functionality would be deployed after successful testing as soon as possible in the morning of the 1st of September.

2023-09-01 05:33:24

Certificate with serial number 01:8a:4f:3b:59:7d:77:27:86:21:49:09:a4:b9:5d was issued via API call to the CA system.

2023-09-01 05:33:56

Certificate with serial number 01:8a:4f:3b:d9:8d:a5:72:17:0e:63:0e:aa:51:e9 was issued via API call to the CA system.

2023-09-01 05:34:14 UTC

Certificate with serial number 01:8a:4f:3c:1d:1d:3f:cb:cf:73:a9:b6:0e:36:91 was issued via API call to the CA system.

2023-09-01 06:00 UTC

Telia CA Development manager made final review and testing of the development and verified the API to meet the S/MIME BR v1.0.1 requirements for certificate profiles.

2023-09-01 06:38 UTC

Changes in the API were deployed and issued certificates after this time meet the requirements of S/MIME BR.

2023-10-02 14:30 UTC

Telia CA Administrator performed monthly compliance review for the S/MIME certificates with pkilintlinter to verify certificate compliance for the month of September 2023.

2023-10-02 14:42 UTC

Telia CA Administrator responsible for monthly compliance review informed Telia CA Security and Compliance manager in the early evening of the 2nd of October 17:42 EET of the incident.

2023-10-03 05:01 UTC

Telia CA Security and Compliance manager initiated immediate review in the morning of the 3rd of October 08:01 EET to confirm and verify the said compliance issue to be factual.

2023-10-03 06:15 UTC

Telia CA's weekly Security Board convened at the 3rd of October 09:15 EET to make final review of the incident and verify need for public incident reporting in accordance with S/MIME BR and Root program policy requirements. Telia CA Security and Compliance manager was designated responsible for public reporting and required internal resources were immediately assigned to collect the evidence for full disclosure report.

Immediate actions were initiated both internally and externally to inform affected persons and to collect details and chain of events to identify all the details why the certificates were in fact mississued.

2023-10-03 07:23 UTC

Full compliance check for all issued S/MIME certificates was executed by Telia CA and other problematic certificates were not found.

2023-10-03 11:35 UTC

Telia CA Security and Compliance manager opened initial incident report in Mozilla Bugzilla.

2023-10-03 11:45 UTC

Apple Root Program was informed about the incident as required by their respective Root Progam Policy.

2023-10-03 11:33 UTC

Customer was informed and asked to revoke and issue new certificates before 2023-10-05 14:00 GMT

2023-10-03 11:49 UTC

One certificate was revoked by customer

2023-10-05 14:46 and 2023-10-05 14:48 UTC

The other two certificates were revoked by CA

2023-10-05 14:50 UTC

Filed incident was updated by Telia CA Security Manager to inform completed revocation of the problematic certificates.

2023-10-06 04:03 UTC

Minor update on the revocation details updated to this incident report.

2023-10-10 12:52 UTC

Full disclosure report updated to this incident report by Telia CA Security Manager.

3. Whether your CA has stopped

or has not yet stopped, certificate issuance or the process giving rise to the problem or incident. A statement that you have stopped will be considered a pledge to the community; a statement that you have not stopped requires an explanation.

The issuing CA was not stopped. The events leading to the misissuance of the certificates explained in this report (in particular in section 6 of this report) explain why the CA was not stopped from issuance.

4. In a case involving certificates, a summary of the problematic certificates.

For each problem: the number of certificates, and the date the first and last certificates with that problem were issued. In other incidents that do not involve enumerating the affected certificates (e.g., OCSP failures, delayed responses, etc.), please provide other similar statistics, aggregates, and a summary for each type of problem identified. This will help measure the severity of each problem.
When the incident being reported involves an SMIME certificate,
if disclosure of personally identifiable information in the certificate may be contrary to applicable law, please provide at least the certificate serial number and SHA256 hash of the certificate. In other cases not involving a review of affected certificates, please provide other similar, relevant specifics, if any.

Personally identifiable information must be kept undisclosed under the provisions of the European Union General Data Protection Regulation (Regulation (EU) 2016/679, GDPR), therefore only technical details of the certificates are disclosed.

List of problematic certificates:

Certificate 1, issued on the 2023-09-01 05:33:24 UTC and revoked on the 2023-10-05 13:48:12 UTC
Serial HEX: 01:8a:4f:3b:59:7d:77:27:86:21:49:09:a4:b9:5d
serial DEC: 7997546776479856255670047314590045
SHA256 fingerprint: 9D:EF:1B:B2:76:A3:E1:77:9C:8E:50:7D:64:EE:BF:2C:A4:18:C5:0F:60:FA:D3:4A:9F:16:BF:DF:81:7D:32:BF

Certificate 2, issued on the 2023-09-01 05:33:56 UTC and revoked on the revoked 2023-10-03 11:49:50 UTC
Serial HEX: 01:8a:4f:3b:d9:8d:a5:72:17:0e:63:0e:aa:51:e9
serial DEC: 7997546931298772953350938101961193
SHA256 fingerprint: 50:5F:8B:04:6A:FD:05:51:7E:A6:ED:DB:C0:E1:FC:FC:B5:6E:A3:6F:86:D5:FA:C0:1D:49:1C:C0:E3:C1:C7:66

Certificate 3, issued on the 2023-09-01 05:34:14 UTC and revoked on the 2023-10-05 13:46:49 UTC
Serial HEX: 01:8a:4f:3c:1d:1d:3f:cb:cf:73:a9:b6:0e:36:91
serial DEC: 7997547012974948538197422564587153
SHA256 fingerprint: D8:03:FC:DB:AC:91:CA:96:98:ED:B3:D1:E9:ED:2E:FF:82:64:3C:D5:B8:37:7E:CC:48:AD:26:0B:5B:35:2E:87

6. Explanation about how and why the mistakes were made or bugs introduced, and how they avoided detection until now.

As explained above in section 2 the final review of an API for technically constrained intermediate CA for S/MIME BR compliance identified issue with the said API missing required functionality. As the final review took place in the afternoon of 31st of August there wasn't enough time to have the functionality in place on time. The decision made by the Development Manager of the said API was to commence the development immediately, but the final product was available for final testing only in the morning of the 1st of September.

Mistake was made in impact analysis phase of the delayed development of the required API functionality that did not consider the API deactivation for the period of time before the required API functionality could be deployed. This lead to situation where pre S/MIME BR based functionality was available for the said CA via the API and made possible for the customer to request three (3) certificates before the update was applied in the morning of the 1st of September. Further the Development Manager did not check / verify if there actually were certificates created via the API in the early hours of the 1st of September, thus these two factors lead to the possiblity to issue three certificates in violation of the S/MIME BR v1.0.1.

Due to above explained chain of events the misissued S/MIME certificates were undected until the monthly compliance review of all Telia CA certificates subject to S/MIME BR v1.0.1 at the 2nd of October by the CA Admistrator responsible for the monthly compliance check.

7. List of steps your CA is taking to resolve the situation and ensure that such a situation or incident will not be repeated in the future.

The steps should include the action(s) for resolving the issue, the status of each action, and the date each action will be completed.

  • Step / task 1:
    • Verification of existing functionality deployed in CA to ensure that such misissuance cannot re-occur
    • Done 9.10.2023, all systems have been verified by the CA to meet the S/MIME BR requirements and thus not able to issue non-conformant certificates of similar kind that explained in this incident report.
  • Step / task 2:
    • Pre-deployment testing to be more extensive and done well before the ultimate deadline to prevent issues at very late stage just before planned deadline.
      • Define and establish more explicit milestones for readiness verification checklist to ensure that holistic review of changes shall be done in completion earlier in the continuous delivery process of Telia CA system and software development.
      • Full readiness review for full CA system scope shall be added to the final readiness checklist.
      • To be in place by end of November 2023 with all required activites
  • Step / task 3:
    • After-deployment checklist to contain compliance verification immediately after new functionality has been deployed
      • Verification checks may be manual or automatic dependent on case-by-case basis
      • To be in place by end of November 2023 with all required activites
  • Step / task 4:
    • Deploy daily linting of issued S/MIME certificates instead of relying on monthly compliance verfication
      • To be in place by end of Q4/2023
Whiteboard: [ca-compliance] [smime-misissuance] → [ca-compliance] [smime-misissuance] Next update at 30.11.2023

This is to report that Tasks 2 and 3 has been fully satisfied and deployed as planned.

Telia CA follows periodaclly progress on this incident and is prepared to duly respond to request concerning this incident.

Next update as defined by 'Next update'

Whiteboard: [ca-compliance] [smime-misissuance] Next update at 30.11.2023 → [ca-compliance] [smime-misissuance] Next update at 29.12.2023

This is to update that Telia CA has deployed daily linting with digicert/pkilint tool to verify S/MIME certificate compliance in accordance with CA/B Forum S/MIME Baseline Requirements.

This completes the remedial actions planned for this incident.

Telia CA shall continue to monitor this incident. Next update by nextupdate

Whiteboard: [ca-compliance] [smime-misissuance] Next update at 29.12.2023 → [ca-compliance] [smime-misissuance] Next update at 26.1.2024

Telia CA continues to monitor this incident, next update by Next update unless this incident is closed prior that.

As there has not been any further questions / comments on this incident since about a month ago and all planned tasks / actions have been completed, Telia CA is kindly requesting this incident to be closed.

Flags: needinfo?(bwilson)
Whiteboard: [ca-compliance] [smime-misissuance] Next update at 26.1.2024 → [ca-compliance] [smime-misissuance] Next update at 23.2.2024

I'll close this tomorrow - Friday, 26-Jan-2024.

Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Flags: needinfo?(bwilson)
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.