E-Tugra: Improper DER results in failure to comply with RFC 5280 (invalid PrintableString characters)
The case concerns an E-Tugra certificate that fails to parse due to invalid characters in a Subject serialNumber field: the serialNumber contains an underscore (“_”), which is not valid for a PrintableString, and the certificate also includes a Subject attribute with a serialNumber field. Ryan Sleevi (Mozilla) provided an example certificate URL and stated it appears to be a misissued certificate and asked E-Tugra to provide an incident report. E-Tugra responded that it continued reviewing the case and later provided an incident report describing how it became aware of the problem and what actions it took. E-Tugra stated it revoked the affected certificates (including those reported in Bugzilla) and issued a replacement certificate for the certificate owner, with revocation planned “in a week” in the earlier response. E-Tugra also reported that it searched its certificate database and found no other certificates with the same problem, upgraded its pre-issue and post-issue control libraries, and rebuilt certificate issue controls based on RFC 5280 and CA/Browser Forum Baseline Requirements, with controls put into use on Jan 31. Fastly’s wthayer later commented that it appears remediation is complete, and the bug is marked RESOLVED with resolution FIXED.
- A misissued E-Tugra certificate example was identified as failing to parse due to invalid PrintableString characters in a Subject serialNumber field.
- E-Tugra revoked the certificates it identified as affected, including those reported in the Bugzilla case.
- E-Tugra reported that system upgrades rebuilt certificate issue controls and that reasons for the problems were fixed with auto control and alerting introduced.
- A reviewer stated it appears remediation is complete.
- Community commenter — Provided an example certificate URL and explained it fails to parse because the Subject serialNumber contains an underscore, which is not valid for PrintableString.
- Fastly representative — Agreed it appears to be a misissued certificate and requested an incident report posted to the mozilla.dev.security.policy forum and added to the bug.
- E-Tugra — Said E-Tugra would provide an incident report as soon as possible.
- E-Tugra — Explained that invalid certificates were issued during testing of a new intermediate CA, described three levels of certificate controls, and said a detailed report would be posted.
- E-Tugra — Provided an incident-report style response including awareness sources, a timeline of issuance and revocation, and stated controls were rebuilt with pre-issue and post-issue changes.
- Fastly representative — Thanked E-Tugra for the detailed response and said it appears remediation is complete.