SwissSign: Certificate issue with Signature (incident report)
SwissSign reported an incident in which it issued certificates with signature issues. The post-issue compliance system alerted SwissSign on 2018-05-07 02:01 UTC to a problem reported by cablint: “ERROR: RSA signatures must have a parameter specified.” SwissSign stated that it stopped issuing certificates after becoming aware of the problem and released a fix, after which it started issuing certificates again. SwissSign also said it informed customers about the incident and exchanged affected certificates. The report included that 19 certificates were affected, with first issuance on 2018-05-05 09:25:45 GMT and last issuance on 2018-05-07 06:55:57 GMT. SwissSign later stated that all affected certificates were revoked as of 2018-05-09 12:00 UTC, and described adding internal pre-issuance linting to prevent recurrence. The bug was resolved, and SwissSign later noted that pre-issuance linting for newly produced certificates was established and activated in September 2018, and that there had been a lack of notification to Bugzilla due to personnel changes.
- SwissSign issued the first certificates later identified as having RSA signature parameter issues.
- SwissSign’s post-issue compliance system alerted it to the signature-parameter problem and it stopped issuing certificates.
- SwissSign stated that all affected certificates were revoked.
- SwissSign established and activated pre-issuance linting for newly produced certificates.
- SwissSign AG — SwissSign initiated an incident report, stating that its post-issue compliance system alerted it on 2018-05-07 02:01 UTC to a cablint-reported RSA signature parameter error and that it would provide the incident report in this bug.
- SwissSign AG — SwissSign provided a timeline including stopping issuance, releasing a fix, restarting issuance, and informing customers/exchanging affected certificates; it also described the problematic certificates and stated that release 4.11 introduced a change in ASN1 generation that caused the missing RSA signature parameter.
- Fastly representative — Fastly thanked SwissSign and asked that the bug be updated when its staging environment compliance system was live.
- SwissSign AG — SwissSign stated that all affected certificates were now revoked as of 2018-05-09 12:00 UTC.
- SwissSign AG — SwissSign said it would have an internal pre-issue linting system in place by end of June and planned to use it for public trusted SSL certificates by end of July.
- SwissSign AG — Juerg Eiholzer stated that pre-issuance linting was established and activated in September 2018, and that the item could be resolved; he also noted a lack of notification to Bugzilla due to personnel changes.