SwissSign: Certificate issued with too long validity period (reissue option misuse)
SwissSign reported that it had issued an SSL certificate with a too-long validity period. The CA said it became aware of the problem when its CABLint post-issue test system alerted it on the evening of 6 March 2018, and it also received emails from an external source. SwissSign stated it started an investigation, contacted the customer to replace the certificate and revoke the mis-issued one, and then revoked the certificate on 7 March 2018. The CA identified the source as incorrect use of a rarely used reissue option available only to SwissSign support employees, and said it immediately prohibited any use of this functionality until it was fixed (ETA 17 March 2018). In its incident report content, SwissSign described that the support option was not in scope during initial implementation work and that support staff were trained to use the functionality with caution in the interim. SwissSign later reported that it would begin pre-issuance linting for all public trusted SSL certificates in early July and provided an update that pre-issuance linting was activated in September 2018; the bug was resolved as FIXED. The thread also includes requests to email the incident report to the mozilla.dev.security.policy forum and follow-up questions about why the code path was not patched earlier.
- CABLint post-issue test system alerted SwissSign to the too-long validity issue.
- SwissSign issued the mis-issued SSL certificate and subsequently revoked it after investigating and contacting the customer.
- SwissSign planned rollout of fixes to constrain the reissue functionality to 825 days for SSL certificates.
- SwissSign activated pre-issuance linting for newly produced certificates.
- SwissSign AG — SwissSign informed Mozilla it had issued an SSL certificate with a too-long validity period and said it would provide an incident report per Mozilla’s misissuance incident report guidance.
- Community commenter — A duplicate marker was set indicating Bug 1443733 was marked as a duplicate of this bug.
- SwissSign AG — SwissSign posted the incident report details, including how it discovered the issue, its response steps, the identified cause (misuse of a rarely used reissue option), and immediate/expected remediation actions including prohibiting the functionality and constraining reissue to 825 days.
- Fastly representative — Fastly requested that the incident report be emailed to the mozilla.dev.security.policy forum and asked follow-up questions about why the code path wasn’t patched and when pre-issuance linting would begin.
- SwissSign AG — SwissSign stated it would email the incident report to the mozilla.dev.security.policy forum and noted it had also posted it on the forum.
- Fastly representative — Fastly thanked SwissSign and asked again for answers to the questions from the earlier comment.
- SwissSign AG — SwissSign answered why the code path wasn’t patched earlier and stated it would have a pre-issuance linting system in place by end of June and start using it in early July.
- SwissSign AG — SwissSign reported it was in quality assurance for the pre-issuance linting system and planned to place it into operation product by product in the coming months.
- SwissSign AG — SwissSign stated pre-issuance linting for newly produced certificates was established and activated in September 2018 and that the item could be resolved, noting a lack of notification to Bugzilla.