← Apple Inc. cases
Bugzilla #1955365
Certificate Problem Report
Apple: Public Key Reuse
RESOLVED
FIXED
Apple Inc.
AI Summary
Apple identified a race condition in its certificate issuance systems that allowed multiple certificates to be issued for the same public key when requests were made simultaneously. This issue affected 44 certificates, all of which were revoked promptly. The incident was self-reported, and Apple has since implemented a two-stage database transaction to prevent future occurrences. The company updated its Certificate Policy Statement to reflect these changes and has committed to improved detection mechanisms for similar issues.
Chronology
- Race condition identified in certificate issuance systems.
- Preliminary Incident Report published.
- CPS updated to remove conflicting statements.
- Report Closure Summary published.
Participants
certification_authority@apple.com
rowleylaw@gmail.com
bwilson@mozilla.com
incident-reporting@ccadb.org
chrome-root-program@google.com
External References
Similar Local Cases
Apple: Revocation Delay for TLS certificates issued outside the TTL of the CAA record
Apple: EV Certificate Approver Authorization
Apple: TLS certificates issued outside the TTL of the CAA record
Apple: OCSP availability 2020-11-12
Apple: CRLs for dormant CAs will not be populated in CCADB
Apple: Test website certificates expired
Apple: OCSP responders return ‘unknown’ for valid S/MIME and TLS certificates
Apple: OCSP responders return responses with incorrect issuer