EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate
The case was opened after an external reporter told EDICOM that its OCSP responder signs OCSP responses with SHA-1 using a certificate trusted by Mozilla for server authentication, which the reporter said violates Mozilla Root Store Policy 2.5 section 5.1.1. The reporter also raised a security concern related to chosen-prefix attacks because the OCSP response reflects an attacker-supplied nonce. EDICOM later stated that it had technical issues disabling SHA-1 when signing OCSP responses and decided not to continue supporting the previous Certification Authority Root. EDICOM said it would proceed with including a new root (referenced as Bug 1239329) and suggested starting the process to remove its “ACEDICOM Root” from the trusted PKI root. Mozilla staff indicated that the bug could be resolved with the outcome of removing the root, and later the Security Issue flag was agreed to be removed. The bug is marked RESOLVED with resolution FIXED.
- A report was filed alleging EDICOM’s OCSP responder signs OCSP responses with SHA-1 using an unconstrained certificate.
- EDICOM stated it could not disable SHA-1 for OCSP signing and decided to move away from the previous root.
- Mozilla filed a request to remove the old ACEDICOM root certificate (Bug 1400013), while the new root inclusion request remained on hold pending a BR self-assessment.
- Mozilla indicated the bug could be resolved based on removing the root.
- The Security Issue flag was agreed to be removed and made public.
- Mm representative — Reported that EDICOM’s OCSP responder signs OCSP responses with SHA-1 using a certificate trusted for server authentication, citing a Root Store Policy violation and attaching evidence.
- Mozilla representative — Asked Raúl to acknowledge the bug promptly, provide a timeline, and submit an incident report.
- Edicom representative — Said EDICOM found technical issues disabling SHA-1 for OCSP signing and decided not to support the previous root; suggested starting removal of the old ACEDICOM root and referenced the new root inclusion process.
- Mozilla representative — Stated she filed Bug 1400013 to remove the old ACEDICOM root and noted the new root inclusion request was on hold pending a BR Self Assessment.
- Mozilla representative — Asked whether the bug could be resolved with the outcome of removing the root.
- Community commenter — Suggested removing the Security Issue flag.
- Mozilla representative — Agreed to remove the Security Issue flag and said she would ask someone to fix it.
- Emmah representative — Confirmed making the change public per Kathleen.