SHA-1 issuance by DigiCert roots
The bug was opened after Mozilla security policy discussions identified SHA-1 certificates chaining up to Mozilla-trusted DigiCert roots that had not been brought up on the list or in Bugzilla. DigiCert representatives responded that the affected issuing CAs were outside DigiCert’s direct control, and they worked with those partners to determine what happened. For Vodafone, DigiCert stated that Vodafone controls the issuing CA, that Vodafone was migrating to new SHA-2 infrastructure with audits scheduled, and that DigiCert had communicated to partners that SHA-1 use is forbidden. For Siemens, DigiCert stated the Siemens issuing CA is under Siemens Europe control and described it as a legacy CA they hoped to decommission, while later Siemens provided details including that SHA-1 issuance was prevented by their Server RA software and that two specific SHA-1 certificates were issued due to an erroneously applied exception process, after which the certificates were revoked and employees re-informed. The Mozilla bug was ultimately marked WONTFIX, with Mozilla stating that as long as DigiCert continues its plan and takes robust action about further SHA-1 issuance, no further action would be taken. The thread also included discussion of revocation scheduling and a plan to revoke at least one intermediate for failing to fix issuance systems, with a proposed revocation date of Dec 1.
- A Mozilla CA Program bug was filed regarding SHA-1 certificates chaining to DigiCert roots.
- DigiCert provided partner-specific explanations for Vodafone and requested to post separate replies per incident.
- DigiCert stated it would revoke a Nets Norway intermediate and discussed a revocation schedule.
- Mozilla set the bug to WONTFIX based on DigiCert’s stated plan and actions.
- Mozilla representative — Gerv cited mozilla.dev.security.policy posts listing SHA-1 certificates chaining to DigiCert roots and asked DigiCert to explain CP/CPS, audit status, control of issuing CAs, and technical enforcement.
- Mozilla representative — Kathleen asked Jeremy to look into the issue and update the bug with the requested information.
- DigiCert — Jeremy said separate replies per incident were acceptable and provided Vodafone-related answers about SHA-1 prohibition, audit scheduling, and control of the issuing CA.
- DigiCert — Jeremy provided Siemens-related information, stating Siemens controls the issuing CA and that DigiCert had communicated with Siemens about the BR breach.
- Mozilla representative — Gerv agreed that separate replies for each incident were fine.
- Eishundo representative — Pat compared the situation to another SHA-1-related issue and suggested revocation and adding to revocation lists, referencing other bugs.
- DigiCert — Jeremy stated they decided to revoke the Nets Norway intermediate, discussed a proposed revocation schedule, and described reliance on audits plus plans for monthly/quarterly statements and cablint checks.
- Mozilla representative — Gerv set the bug to WONTFIX, pointing to a mozilla.dev.security.policy thread and stating no further action would be taken if DigiCert continues robust action.
- Community commenter — Ben Wilson posted Siemens’ statement describing CP/CPS algorithm handling, Siemens audit approach, control of the issuing CA, and details of erroneous exception-based SHA-1 issuance followed by revocation and employee re-informing.