E-Tugra: Validity period > 825 days
This case concerns an E-Tugra certificate that contained multiple Baseline Requirements errors, including a validity period greater than allowed (over 825 days). The issue was reported externally by Wayne Thayer (Fastly) with a reference to the certificate on crt.sh and a request for an incident report. E-Tugra stated it took action to fix the problem, including revoking the related certificate and issuing a new certificate for the certificate owner, and searching its certificate database for additional instances. In its incident report, E-Tugra described that it implemented an 825-day validity limit on February 21, 2018, but that due to payment latency the certificate was issued with approved data that covered a validity date over 825 days; E-Tugra also described additional issues involving missing localityName/stateOrProvinceName and an unallowed key usage (key agreement) for RSA public key. E-Tugra reported that it found no more certificates with the 825-day validity problem, replaced another certificate with the localityName/stateOrProvinceName issue, and set server certificates to address the key-agreement flag issue. The bug was marked resolved after the updated incident report and follow-up discussion, and the resolution is FIXED.
- A certificate was issued with a validity period that exceeded the 825-day limit (as described in the incident report).
- A Bugzilla report was filed identifying Baseline Requirements errors in the certificate, including validity period > 825 days.
- E-Tugra stated it revoked the certificate and planned to provide an incident report after root analysis.
- E-Tugra submitted an updated incident report describing causes and remediation steps for the identified BR violations.
- The reporter confirmed the updated incident report and marked the bug resolved.
- Fastly representative — Reported that the certificate had errors including a validity period greater than allowed and requested an incident report, linking to crt.sh.
- E-Tugra — Said E-Tugra would fix the problem, that the certificate was being revoked as soon as possible, and that the incident report would follow after root analysis.
- E-Tugra — Provided an incident report describing revocation, database search, root cause analysis, system library upgrades/testing, and steps to prevent recurrence.
- Fastly representative — Requested reporting on additional BR violations found in the certificate (missing localityName/stateOrProvinceName and unallowed RSA key usage for key agreement).
- E-Tugra — Indicated the incident report would be updated ASAP.
- E-Tugra — Submitted an updated incident report covering the additional BR violations and remediation, including replacing another affected certificate and removing/fixing the key-agreement flag issue.
- Fastly representative — Acknowledged the updated report, discussed the key-agreement flag rationale and fix, and marked the bug resolved.