Trustis: SHA-1 serverAuth certificates issued in November 2016 (hmrcset.trustis.com and getset.trustis.com)
This case concerns Trustis certificates for serverAuth that were reported as SHA-1/RSA certificates issued in November 2016. The initial report described an unrevoked SHA-1 serverAuth certificate for hmrcset.trustis.com and noted it lacked the SAN extension, while also stating it was still subject to Mozilla’s ban on SHA-1. Trustis later reported that it revoked the hmrcset.trustis.com SHA-1 certificate and replaced it with a SHA-256 certificate, with the revocation reflected in the latest CRL. The incident report was followed by another report of an unrevoked SHA-1 serverAuth certificate for getset.trustis.com issued shortly after the first one. In response to questions about SHA-1 profiles, Trustis stated that its investigation was not full enough to discover the second SHA-1 certificate and that it had engaged external auditors, with further information pending. Following further discussion and Mozilla guidance, it was determined that the getset.trustis.com certificate issued in November 2016 was a mis-issuance, and Mozilla indicated the bug could be closed. The bug is marked RESOLVED with resolution FIXED.
- Trustis issued a SHA-1 serverAuth certificate for getset.trustis.com (Not Before date 2016-11-07).
- Trustis issued a SHA-1 serverAuth certificate for hmrcset.trustis.com in November 2016.
- Trustis revoked the hmrcset.trustis.com SHA-1 certificate and replaced it with a SHA-256 certificate.
- An additional report was made for an unrevoked SHA-1 serverAuth certificate for getset.trustis.com, and questions were raised to the CA about SHA-1 profiles.
- Trustis reported it had engaged external auditors and would provide further information after that activity concluded.
- Mozilla determined the getset.trustis.com certificate was a mis-issuance and indicated the bug could be closed.
- Community commenter — Reported the forum incident about an unrevoked SHA-1 serverAuth certificate for hmrcset.trustis.com and included Trustis updates that it revoked and replaced the certificate with SHA-256, then noted a subsequent report of another SHA-1 serverAuth certificate for getset.trustis.com.
- Trustis representative — Reiterated the incident details and stated that Trustis’ investigation was not full enough to discover the second SHA-1 certificate, and that it had engaged external auditors; Mozilla then stated the getset.trustis.com certificate was determined to be a mis-issuance and the bug could be closed.