DigiCert: Use of forbidden subjectPublicKeyInfo algorithm (P-521)
This case concerns certificates issued by DigiCert that used the forbidden subjectPublicKeyInfo algorithm P-521. The issue was reported in the mozilla.dev.security.policy forum and the bug asked DigiCert to provide an incident report. DigiCert identified three certificates issued after the effective date of Mozilla policy 2.4 that used P-521, and Jeremy Rowley stated they were looking into why they were issued after Feb 28, 2017. DigiCert said it blocked all issuance of the certificates in August 2017 and patched the CA to prevent P-521 certificates for any publicly trusted certificates. DigiCert also discussed revocation timing, stating that the certificates were technically compliant with CAB Forum requirements but not with Mozilla policy, and that they were working on internal reviews and governance changes to better capture past and future policy changes. The bug was marked RESOLVED with resolution FIXED.
- DigiCert issued a publicly trusted server CA certificate using P-521 after Mozilla policy 2.4 was released.
- DigiCert issued another publicly trusted server CA certificate using P-521 after Mozilla policy 2.4 was released.
- DigiCert issued a third publicly trusted server CA certificate using P-521 after Mozilla policy 2.4 was released.
- DigiCert blocked issuance of the affected certificates.
- Mozilla requested DigiCert provide an incident report after certificates using P-521 were reported in mozilla.dev.security.policy.
- DigiCert provided a timeline and remediation steps, including process changes and the CA patch to prevent P-521 issuance.
- Community commenter — Reported that problems were found in certificates issued by DigiCert and asked DigiCert to provide an incident report, citing P-521 certificates discussed in mozilla.dev.security.policy.
- Community commenter — Requested that Jeremy provide an incident report on behalf of DigiCert.
- DigiCert — Listed three certificates issued after policy 2.4’s effective date that used P-521 and said they were looking into why they were issued after Feb 28, 2017.
- DigiCert — Provided steps to reproduce and a response timeline, stating they blocked all issuance in August 2017 and describing compliance governance changes.
- DigiCert — Stated the fix was to patch the CA to prevent P-521 certificates for any publicly trusted certificates.
- Community commenter — Asked what processes or controls changed to ensure timely retroactive review and revocation, referencing the comment about not reporting/revoking the certificate issued after Jun 23.
- DigiCert — Explained the revocation debate, stating the certificates were CAB Forum compliant but not Mozilla policy compliant, and described future and past compliance review efforts.
- Community commenter — Flagged a question for Wayne on whether Mozilla policy violations should be treated as BR violations and noted ambiguity created by BR revocation changes.
- Fastly representative — Provided an interpretation that Mozilla policy does not set revocation requirements for these certificates and suggested policy clarification.
- Community commenter — Agreed the remediation steps described in the thread could resolve the issue and referenced a linked message in mozilla.dev.security.policy.