Closed Bug 2057353 Opened 1 month ago Closed 1 month ago

DigiCert or Microsoft: Incorrect disclosure of intermediate certificate

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED INVALID

People

(Reporter: agwa-bugs, Assigned: dcbugzillaresponse)

Details

(Whiteboard: [ca-compliance] [disclosure-failure] [external])

DigiCert has disclosed the intermediate certificate 64FE47E1256083CDAA1FE17AB2D3D965919FAD9CFE063A45A85F62487F88047E as being operated under their CP/CPS.

However, the same key and subject appears in the intermediate certificate 04396B0ED932A93150457013D839077784BFB143EA900B6A4990FCA139CBD4D1, which Microsoft has disclosed as being operated under their CP and CPS.

Someone has incorrectly disclosed an intermediate.

Thank you, Andrew. We are investigating and will file a preliminary report as required by CCADB policy.

Thank you for the report. The reported pair is certificate 64FE47E1256083CDAA1FE17AB2D3D965919FAD9CFE063A45A85F62487F88047E (DigiCert's cross-certificate) and 04396B0ED932A93150457013D839077784BFB143EA900B6A4990FCA139CBD4D1 (Microsoft's retained certificate for the same subordinate). There are six cross-certificates with the same CP/CPS scoping in CCADB.

After review, we believe the disclosures are accurate and compliant with the CCADB policy. We request that this report be closed as INVALID.

Summary

Each affected certificate is a cross-certificate issued from a DigiCert Global Root (G2/G3) to a subordinate CA whose private key is held and operated by Microsoft. Microsoft's disclosure of these subordinates under its own CP/CPS is correct, and, absent specific guidance in the CCADB Policy, DigiCert's usual practice is likewise to attribute a cross-signed subordinate to the operating partner's CP/CPS.

The CCADB policy is unclear on which CP/CPS should be used in this particular case, and, given the lack of guidance, we believe the approach used is the correct one. In this case, none of the six cross-certificates were used to issue end-entity certificates. All of them are revoked and were revoked prior to any related use by Microsoft. The two primary auditable events in these cross-certificate lifecycles were their signing by DigiCert and their revocation by DigiCert. On that basis, we concluded that the DigiCert CP/CPS dictated their lifecycle and use instead of the Microsoft CP/CPS. This means the issued and revoked cross-certs should be in DigiCert’s audit and under our control, even if they were originally intended for use by Microsoft. Because these certificates have not yet appeared on any audit statement, we will include them in the next DigiCert WebTrust audit, consistent with CCADB Policy §5.1.

Affected certificates

https://crt.sh/?sha256=64FE47E1256083CDAA1FE17AB2D3D965919FAD9CFE063A45A85F62487F88047E
https://crt.sh/?sha256=6EC85CD93E5A7B4CAE58818CB0296A80B3B23AC8D7268E48882E53700F1544A8
https://crt.sh/?sha256=39C492D06ED1150D35FCEACF0DF28D0FB61BBA072A34AA4E824D6BE339A7EB23
https://crt.sh/?sha256=3ED3F8679802E0ABEEDB388A901DAF619B6F2B34F6926DCCFFF2139517351178
https://crt.sh/?sha256=3BFBAB94D8573CF5501E87273833172EE3B2184FFFFD9B95A3906FC4DD3ADA50
https://crt.sh/?sha256=DED374DC72904DCCAFB7DCD8429D45A6AADAB8028FD7C70CB1A0BD53FE0CCC6E

All carry subject organization Microsoft Corporation and the CA/B Forum Organization Validated policy; keyUsage {digitalSignature, keyCertSign, cRLSign} (critical); EKU id-kp-serverAuth. All certificates are revoked with revocation reasonCode 'superseded'. The revocations were administrative, with no security concern.

Why we ask for INVALID

  • The certificates were validly issued and their operation was uploaded to CCADB in accordance with the requirement. The cross-signs were not used and were revoked upon request by Microsoft.
  • CCADB Policy does not specify which CA Owner's CP/CPS a cross-certificate record must reference, especially one that is revoked before they are used, nor does it require the two records for one subordinate to match. Placing these under DigiCert's CP/CPS and audit scope reflects that DigiCert was the primary party with lifecycle action items.

We would welcome clarification in a future version of the CCADB Policy on the expected CP/CPS attribution for cross-signed subordinate CAs.

Flags: needinfo?(incident-reporting)

The "Subordinate CA Owner" field of 64FE47E1256083CDAA1FE17AB2D3D965919FAD9CFE063A45A85F62487F88047E is blank.

The CCADB policy states:

CA Owners MUST NOT leave this field blank unless both control of the private key and domain/IP control validation activities are performed by the organization listed in the audit statement of the parent certificate.

Since DigiCert does not control the private key, it's a non-compliant disclosure.

Assignee: nobody → dcbugzillaresponse
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [disclosure-failure] [external]

Thank you for the follow-up.

The issue raised in Comment 3 is different from the original subject of this bug. For the sake of clarity :

  1. we have opened a new Bug 2058363 focused on the new issue, and
  2. request this bug be closed as INVALID.
Flags: needinfo?(incident-reporting)

Given the existence of Bug 2058363, we will mark this bug resolved with a status of INVALID.

Status: ASSIGNED → RESOLVED
Closed: 1 month ago
Flags: needinfo?(incident-reporting)
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.