DigiCert / InfoCert: Insufficient Serial Number Entropy (sub CA incident report)
This case is an incident report for a DigiCert sub CA under the InfoCert hierarchy, concerning insufficient serial number entropy. The bug was separated out from Bug 1389172 to request an incident report specific to this sub CA. DigiCert stated it first became aware of the problem via a certificate problem report received on August 10. DigiCert said the sub CA was revoked in June 2017, but that it forgot to upload the sub CA to OneCRL until right after receiving the certificate problem report. DigiCert also stated that it stopped issuance by revoking the sub CA, and that the InfoCert issues cannot happen again. For remediation, DigiCert said it is implementing closer monitoring for mis-issuances and, as a process change, will add sub CAs to OneCRL before revoking and create a revocation checklist for intermediates. The bug was resolved as FIXED.
- The InfoCert sub CA was revoked (as described by DigiCert in the thread).
- DigiCert stated the sub CA revocation date as August 1, 2017 and later updated CCADB accordingly.
- DigiCert added the revocation to the CCADB (per a thread correction).
- DigiCert changed OneCRL status to Ready to Add (per the thread correction).
- DigiCert received a certificate problem report email and identified the OneCRL upload gap.
- DigiCert described process remediation: add sub CAs to OneCRL before revoking and create a revocation checklist.
- Mozilla representative — Opened the separated bug to request an incident report specific to the InfoCert sub CA and asked for details per Mozilla’s incident report guidance.
- DigiCert — Provided incident-report answers, stating the problem was reported via a certificate problem report on August 10 and that the sub CA was revoked but not uploaded to OneCRL until after the report.
- Community commenter — Asked what process changes DigiCert made to ensure timely upload to OneCRL for external sub CA relationships.
- Community commenter — Corrected revocation and CCADB/OneCRL dates, stating the sub CA was revoked on August 1, CCADB updated on August 4, OneCRL status set to Ready to Add on August 7, and the issue was discovered on August 10 via an email to the Mozilla Dev Security Policy list.
- DigiCert — Described remediation steps: add sub CAs to OneCRL before revoking and create a revocation checklist for intermediates.
- DigiCert — Asked whether the bug was ready to close and if more information was needed.
- Community commenter — Questioned the discrepancy between revocation dates referenced in earlier comments and the CRL’s suggested date.
- DigiCert — Attributed the date discrepancy to pulling information from the CCADB while tired, and apologized for the confusion.