Amazon Trust Services: Test revoked certificates with invalid validity period
Amazon Trust Services disclosed that it had issued “test revoked” certificates intended for software vendors to test revoked certificates. The certificates were created with an incorrect validity period of 39 months and an incorrect subject that made them appear to be EV certificates. Amazon stated that after running cablint on the certificates on 2/1/2019, it discovered that the revoked certificates were incorrectly formatted and identified as EV certs with 39 months validity. Amazon said it would not issue test revoked certificates with an incorrect validity or subject again, and reported remediation steps including updating the script to default test revoked certificates to 13 months and adjusting the guardrail so these test certs cannot exceed 825 days, and updating the commands template to use the correct subject. Amazon also described process changes for offline issuance, including requiring artifact review before and after signing against its CPS and adding linting both prior to and following issuance. A Fastly participant later commented that remediation appeared complete. The bug is marked RESOLVED with resolution FIXED.
- Amazon Trust Services created five test revoked certificates and revoked them about a minute later.
- Amazon Trust Services ran cablint during post-ceremony validation and discovered the revoked certificates were incorrectly formatted (EV-like subject and 39-month validity).
- Amazon Trust Services provided crt.sh links listing the problematic certificates.
- Amazon Trust Services explained the cause and described updates to its offline issuance process and linting/artifact review steps.
- A participant stated that remediation appeared complete.
- Community commenter — Ryan Sleevi opened the disclosure describing the incorrect 39-month validity and EV-like subject for test revoked certificates, how cablint discovered the issue on 2/1/2019, and the remediation steps Amazon took.
- Community commenter — Trevoli provided a list of the problematic certificates via crt.sh links.
- Community commenter — Trevoli explained the underlying cause (template/guardrail not updated for Ballot 193 changes and missing artifact review in offline issuance) and described process updates to review artifacts and lint before and after issuance.
- Community commenter — Wayne Thayer commented that remediation is complete.