Closed Bug 1861782 Opened 2 years ago Closed 2 years ago

IdenTrust: S/MIME certificates with Invalid document Identification Scheme

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: roots, Assigned: roots)

Details

(Whiteboard: [ca compliance] [smime-misissuance])

Attachments

(1 file)

10.70 KB, application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
Details

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36

Steps to reproduce:

<h2>Incident Report</h2>
<h3>Summary</h3>
On 2023-10-23, our customer support team confirmed that customers retrieving S/MIME Mailbox-Validated certificates were encountering errors due to missing individual identity details. Upon further investigation, it was found that a software release deployed on 2023-10-19, aimed at capturing individual identity validation for S/MIME certificates mistakenly affected S/MIME Mailbox-Validated certificates. These certificates don't necessitate individual identity validation but rather only ownership/control confirmation of the applicant's email address. Through troubleshooting, we also identified that the identity review process for applicants of our Basic Assurance certificate type (S/MIME Individual-Validated Non-Enterprise) involved an outsourced automated service, which, importantly, doesn't mandate physical identity.

<h3>Impact</h3>
This problem specifically impacted our basic assurance certificates, equivalent to S/MIME Individual-Validated for non-Enterprise customers. These are the only certificates where physical validation of individual identity documents was not conducted.

<h3>Timeline</h3>
2023-10-23 15:00 - Customer support team confirmed receiving calls from customers retrieving S/MIME Mailbox-Validated certificates indicating that they were getting an error for not providing individual identity details.
2023-10-23 15:30 – We began investigation.
2023-10-23 19:00 – We Determined the cause for the error: Control not required for Mailbox-Validated certificates.
2023-10-23 19:00 – Suspended the offering of Basic Assurance certificates.
2023-10-23 20:00 – Found 80 active Basic Assurance certificates with identity validation scheme not S/MIME BR Compliant.
2023-10-23 21:30 – Reversed the software change control.
2023-10-23 23:00 – Notified affected customers of certificate revocation no later than 2023-10-27
2023-10-24 15:30 – Removed the offering of Basic Assurance certificates.
2023-10-27 18:30 – Confirmed that all affected certificates were revoked.

<h3>Root Cause Analysis</h3>
The external automated service did not assess the physical validation of applicant identity documents.

<h3>Lessons Learned</h3>
<h4>What went well</h4>

  • We swiftly halted the issuance of this certificate type.
  • All affected certificates were revoked within a span of 5 days.

<h4>What didn't go well</h4>
The timeline for revocation didn't sit well with some of the impacted customers.

<h4>Where we got lucky</h4>

<h3>Action Items</h3>
No further action items are necessary to resolve this issue.

Assignee: nobody → roots
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca compliance] [smime-misissuance]
Type: defect → task

We have no further pending actions for this issue

Can you please close this ticket?

Flags: needinfo?(bwilson)

Unless there are any objections, I will close this ticket on Wed. 3-Jan-2024.

Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Flags: needinfo?(bwilson)
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: