SECOM: failure to revoke certificates with underscore DNS names
SECOM failed to revoke certificates containing DNS names with underscores by the required deadline of 2019-01-15 (CABF ballot SC12). Jonathan Rudenberg notified SECOM via their problem reporting address on 2019-01-29, and SECOM confirmed the certificates were revoked the same day. The thread includes SECOM’s incident report describing when SECOM became aware of the problem and a timeline of actions, stating that seven certificates were revoked on the day of the notice. SECOM also stated it had been aware of the 15-January deadline, but that certificates for confirmation of CA system configuration were recorded in a separate database, which prevented SECOM from recognizing and targeting them during investigation. SECOM said it implemented a system to check that DNS names do not include underscores and to prevent operational mistakes, and later stated that remediation appeared complete. The bug is marked RESOLVED with resolution FIXED.
- SECOM issued two certificates later identified as containing DNS names with underscores.
- SECOM issued four certificates later identified as containing DNS names with underscores.
- SECOM issued one certificate later identified as containing DNS names with underscores.
- The required deadline passed for revoking certificates containing underscore characters in DNS names.
- SECOM was notified and confirmed revocation of the identified certificates the same day.
- SECOM implemented a system to check for underscores in DNS names and prevent operational mistakes.
- Titanous representative — Reported that SECOM failed to revoke underscore-containing DNS name certificates by 2019-01-15 and stated SECOM was notified on 2019-01-29 and confirmed revocation that day, with crt.sh links.
- Fastly representative — Requested an incident report and asked for an explanation if revocation was intentionally delayed.
- Secom representative — Said SECOM was preparing an incident report and would post it the next week.
- Secom representative — Provided an incident report with a timeline, stated the certificates were revoked on the day of notice, and explained the issue with certificates being recorded in a separate database.
- Fastly representative — Asked whether SECOM was aware of the 2019-01-15 deadline and, if so, why the certificates were not detected.
- Secom representative — Confirmed awareness of the deadline and explained that separate database records prevented targeting during investigation; said administrators were notified to check going forward.
- Fastly representative — Asked when SECOM expected implementation of a system to check DNS names for underscores and prevent operational mistakes.
- Secom representative — Stated SECOM implemented the changes that day.
- Fastly representative — Commented that it appears remediation is complete.