IdenTrust: S/MIME certificates with Invalid document Identification Scheme
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: roots, Assigned: roots)
Details
(Whiteboard: [ca compliance] [smime-misissuance])
Attachments
(1 file)
|
10.70 KB,
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
|
Details |
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36
Steps to reproduce:
<h2>Incident Report</h2>
<h3>Summary</h3>
On 2023-10-23, our customer support team confirmed that customers retrieving S/MIME Mailbox-Validated certificates were encountering errors due to missing individual identity details. Upon further investigation, it was found that a software release deployed on 2023-10-19, aimed at capturing individual identity validation for S/MIME certificates mistakenly affected S/MIME Mailbox-Validated certificates. These certificates don't necessitate individual identity validation but rather only ownership/control confirmation of the applicant's email address. Through troubleshooting, we also identified that the identity review process for applicants of our Basic Assurance certificate type (S/MIME Individual-Validated Non-Enterprise) involved an outsourced automated service, which, importantly, doesn't mandate physical identity.
<h3>Impact</h3>
This problem specifically impacted our basic assurance certificates, equivalent to S/MIME Individual-Validated for non-Enterprise customers. These are the only certificates where physical validation of individual identity documents was not conducted.
<h3>Timeline</h3>
2023-10-23 15:00 - Customer support team confirmed receiving calls from customers retrieving S/MIME Mailbox-Validated certificates indicating that they were getting an error for not providing individual identity details.
2023-10-23 15:30 – We began investigation.
2023-10-23 19:00 – We Determined the cause for the error: Control not required for Mailbox-Validated certificates.
2023-10-23 19:00 – Suspended the offering of Basic Assurance certificates.
2023-10-23 20:00 – Found 80 active Basic Assurance certificates with identity validation scheme not S/MIME BR Compliant.
2023-10-23 21:30 – Reversed the software change control.
2023-10-23 23:00 – Notified affected customers of certificate revocation no later than 2023-10-27
2023-10-24 15:30 – Removed the offering of Basic Assurance certificates.
2023-10-27 18:30 – Confirmed that all affected certificates were revoked.
<h3>Root Cause Analysis</h3>
The external automated service did not assess the physical validation of applicant identity documents.
<h3>Lessons Learned</h3>
<h4>What went well</h4>
- We swiftly halted the issuance of this certificate type.
- All affected certificates were revoked within a span of 5 days.
<h4>What didn't go well</h4>
The timeline for revocation didn't sit well with some of the impacted customers.
<h4>Where we got lucky</h4>
<h3>Action Items</h3>
No further action items are necessary to resolve this issue.
Updated•2 years ago
|
Updated•2 years ago
|
Can you please close this ticket?
Comment 3•2 years ago
|
||
Unless there are any objections, I will close this ticket on Wed. 3-Jan-2024.
Updated•2 years ago
|
Description
•