Camerfirma: Non-BR-Compliant Issuance - Non-printable characters in OU field
The bug reports a misissued SSL certificate from AC Camerfirma, S.A. where the certificate’s OU field contained non-printable control characters. The initial report was filed by Wayne Thayer (Fastly) after observing the issue on crt.sh; the certificate had already been revoked. Camerfirma stated it had become aware of the misissue via its daily crt.sh checks on 2018-01-17, contacted the team managing website certificates, and revoked the certificate. Camerfirma also said it stopped issuing certificates of the affected profile until a technical control was deployed, and later reported that a technical control was deployed on 2018-01-26. Camerfirma later explained the cause as an implementation detail in its certificate request entry method that allowed problematic characters to be included in the subject, and it described deploying cablint and x509lint controls on 2018-02-14 to prevent issuance when fatal/error conditions are detected. In follow-up, Camerfirma provided analysis results via a referenced groups.google.com link and stated that all misissued certificates identified in that analysis had been revoked.
- A misissued SSL certificate with non-printable control characters in the OU field was identified and revoked.
- Camerfirma reported that a technical control was deployed to prevent the issue.
- Camerfirma reported deploying cablint and x509lint technical controls to block issuance on fatal/error lint results.
- Camerfirma reported running an automated analysis of issued TSL/SSL certificates to identify misissued certificates related to lint errors.
- Camerfirma reported revocation status for misissued certificates identified in its analysis and stated all identified misissued certificates were revoked.
- Community commenter — Wayne Thayer reported that a SSL certificate was misissued with non-printable control characters in the OU field, noted it was already revoked, and requested an incident report.
- Community commenter — Juan Ángel Martin said Camerfirma had been aware via daily crt.sh checks, corrected the issue, revoked the certificate, stopped issuing the affected profile, and planned a technical control deployment.
- Community commenter — Juan Ángel Martin stated the technical control was deployed at 7:31 (UTC).
- Community commenter — Wayne Thayer requested a full incident report and asked why it happened and why it was not detected earlier, and how it would be prevented.
- Community commenter — Juan Ángel Martin explained the cause as a certificate request entry method allowing problematic characters into the subject, and described the post-issuance detection and the cablint/x509lint controls deployed on 2018-02-14.
- Community commenter — Wayne Thayer asked whether Camerfirma scanned all active certificates and what was found.
- Community commenter — Juan Ángel Martin provided a link to the analysis results.
- Community commenter — Wayne Thayer asked whether all misissued certificates identified in the analysis had been revoked and included the copied analysis text for reference.
- Community commenter — Juan Ángel Martin confirmed that all misissued certificates identified in the analysis had been revoked and noted the bug update location.