DigiCert / ABB: Issues with DN, country code, and keyUsage in ABB intermediate CA certificates
This case concerns DigiCert and ABB intermediate CA certificates that had distinguished-name, country-code, name-constraint, and keyUsage issues. The problem was first brought to DigiCert’s attention on 2018-03-16 by Ryan Sleevi, who pointed to ABB Issuing CA 8 and ABB Intermediate CA 5, and DigiCert later identified ABB Issuing CA 9 as another related certificate. DigiCert explained that it had created multiple versions of ABB Intermediate CA 5 while trying to address ABB’s requests and the name-constraint issues, and later acknowledged that it had not adequately advised ABB on the content requirements for the issuing CAs. The thread also discusses the number of active end-entity certificates under ABB Issuing CA 8 and CA 9, the need to replace them before revocation, and the complications ABB raised about revoking code-signing-related infrastructure. DigiCert reported that ABB revoked CA 9 on 2019-04-19, that CA 5 was revoked on 2019-08-28, and that the remaining certificates under CA 8 were being replaced before revocation. The bug was later treated as ready to close, with remediation described as complete.
- DigiCert created an ABB Intermediate CA 5 certificate with DN and name-constraint issues.
- DigiCert created the fifth ABB Intermediate CA 5 certificate, which became the subject of the incident report.
- DigiCert was notified about ABB Issuing CA 8, ABB Intermediate CA 5, and related certificate problems.
- ABB revoked CA 9 and reported progress replacing certificates under CA 8.
- ABB CA 5 was revoked.
- DigiCert — DigiCert opened the report and described how it learned of the problem, including the affected ABB CA certificates and the initial timeline.
- Fastly representative — Wayne Thayer asked for updates on certificate counts and whether DigiCert still believed cablint was wrong about the DNSName name-constraint issue.
- DigiCert — Tim Hollebeek said DigiCert had concluded dot-prefixed dnsName constraints were unnecessary and non-compliant with RFC 5280.
- DigiCert — DigiCert said CA 8 and CA 9 depended on CA 5 remaining valid and that the last leaf certificates under CA 8 and CA 9 expired on 2020-10-19.
- DigiCert — DigiCert said the CA5-related intermediates had not been disclosed in CCADB because they were technically constrained, and said CA5 was not relevant for Java code signing.
- DigiCert — DigiCert said ABB would be ready to revoke CA 9 by replacing all email certificates by the end of March, and that revoking CA 5 and CA 8 required client trust in the new server chain.
- DigiCert — DigiCert reported that ABB revoked CA 9 and that 192 of 492 certificates under CA 8 had been replaced.
- DigiCert — DigiCert proposed August 30, 2019 as the revocation deadline and said it would post a firm accelerated timeline.
- DigiCert — DigiCert reported that ABB CA 5 had been revoked.
- Fastly representative — Wayne Thayer said it appeared that all questions had been answered and remediation was complete.