Microsec: Validity period greater than 825 days
This case concerns Microsec misissuing three CISCO VPN server certificates to the Hungarian Chamber of State Notaries. The certificates were issued with three years validity instead of two years, which was identified as a problem by Mozilla (notification email from Alex Gaynor on 2018-11-29). After receiving the notification, Microsec ordered replacement certificates with two years validity and informed the customer about the misissuance. Microsec also planned and then carried out revocation of the original misissued certificates. The customer reported on 2018-12-03 that all three certificates had been replaced successfully, and that the misissued certificates were revoked. The thread later states that the discussion completed and no further action was required, and the bug is resolved as FIXED.
- Microsec issued three CISCO VPN server certificates with three years validity.
- Mozilla notified Microsec of two misissued certificates (validity period issue).
- Microsec ordered replacement certificates with two years validity and replacement of all three affected certificates.
- The customer reported replacement completion and revocation of the misissued certificates.
- Fastly representative — Wayne Thayer posted Microsec’s incident report describing how Microsec became aware, the timeline of replacement issuance and planned revocation, and the problematic certificates/validity issue.
- Fastly representative — Wayne Thayer added a link to the related discussion on the mozilla.dev.security.policy mailing list.
- Fastly representative — Wayne Thayer stated the discussion completed and no further action was required.