← Amazon Trust Services cases
Bugzilla #1525710
Certificate Problem Report
Amazon Trust Services: Test revoked certificates with invalid validity period
RESOLVED
FIXED
Amazon Trust Services
AI Summary
Amazon Trust Services reported a misissuance involving test revoked certificates that were incorrectly set with a validity period of 39 months and an incorrect subject, making them appear as EV certificates. The issue was identified during a post-ceremony validation when cablint was run on the certificates. Amazon has since updated their processes to ensure that such misissuances do not occur again, including changes to the default validity period and the review processes for certificate issuance.
Chronology
- Created 5 test revoked certificates.
- Discovered the validity period issue during cablint validation.
- Provided a list of the problematic certificates.
- Confirmed that remediation is complete.
Participants
Ryan Sleevi
Trevoli (Amazon Trust Services)
Wayne Thayer
External References
Similar Local Cases
Amazon Trust Services: Revoked Sample Certs - No SANs
Amazon Trust Services: Revocation Time for Intermediate Certificates
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
CFCA: Invalid TLD in SAN
Camerfirma: MULTICERT certificates with a validity period greater than 825 days
Camerfirma: MULTICERT certificates with a validity period greater than 825 days
SECOM: certificate for which “L” and “ST” not set
TrustCor: Insufficient Serial Number Entropy