WoSign issued SHA-1 SSL certificates and backdated issuance dates via an API parameter
This case concerns WoSign CA Limited issuing SSL certificates that used SHA-1 and had backdated issuance dates. The issue was reported after Christiaan Ottow noted that a StartEncrypt API parameter (caID) could be used to select a CA, and that a test certificate obtained via this API was dated December 20, 2015 and signed using SHA-1. Kathleen Wilson asked WoSign to explain when it was notified, what analysis it performed to identify the affected certificates, and what remediation would be taken. WoSign (Richard) stated it received a report from Computest before Computest publicly disclosed the bug, then checked that only Computest used the bug and deleted the “discard API parameter,” and asked StartCom to stop using the API. WoSign provided details showing two test certificates with issuance times in June 2016 but “not before” dates in December 2015, and stated it revoked the two certificates and did not think they needed to be added to OneCRL. WoSign also described steps to prevent future misissuance, including logging issued SSL certificates to Google and other log servers and advising browsers to distrust WoSign SSL certificates issued after July 5, 2016 that do not include SCT data. The bug is marked RESOLVED with resolution FIXED.
- Two test SSL certificates were issued with issuance times in June 2016 but “not before” dates in December 2015.
- A second test SSL certificate was issued with issuance time in June 2016 but “not before” date in December 2015.
- A report about the StartEncrypt API behavior and the resulting backdated SHA-1 certificates was posted to the mozilla.dev.security.policy forum.
- A Mozilla CA Program bug was filed regarding WoSign’s SHA-1 and backdated SSL certificate issuance.
- WoSign responded with analysis, identified two affected test certificates, and described remediation steps including deleting the API parameter and stopping the API.
- Mozilla representative — Reported that WoSign-issued SSL certificates were backdated and SHA-1, based on a StartEncrypt API caID parameter selecting WoSign, and attached the affected certificate details.
- Mozilla representative — Asked WoSign to answer questions about notification/containment timing, analysis of which SHA-1/backdated certificates were issued, which certificates should be added to OneCRL, and the remediation timeline.
- WoSign CA Limited — Provided an attachment containing two mis-issued certificates.
- WoSign CA Limited — Stated WoSign received a report from Computest before Computest publicized the bug, deleted the discard API parameter, asked StartCom to stop using the API, and identified two test certificates as the only ones issued in this way.
- WoSign CA Limited — Described prevention steps, including logging issued SSL certificates to Google and other log servers and guidance for browsers/customers regarding SCT data.
- Mozilla representative — Reposted the WoSign response details including certificate issuance and “not before” dates and certificate attributes.
- Community commenter — Commented that users couldn’t mark a WoSign certificate as untrusted without untrusting the whole StartSSL CA.
- Mozilla representative — Added a link to additional problems with WoSign SSL certificate issuance process/code.
- Mozilla representative — Noted that Mozilla has taken action regarding WoSign and referenced a policy forum message.