IdenTrust: Discrepancy in values of address fields within CN of SSL Certificates
IdenTrust reported a discrepancy discovered during an internal systems review on 2019-02-04 involving the Locality, State, and Country values in the Subject field of some SSL certificates, compared to the values on record for the applicant organization. The CA stated that the discrepancy existed in 12 SSL certificates and that it was introduced during a renewal request with specific actions by the applicant. Id enTrust said it stopped issuing certificates with this discrepancy as of 2019-02-04, and it implemented a procedural fix on 2019-02-04 with a permanent production system fix on 2019-02-05. The CA reported that the 12 affected certificates were revoked within 4 days, and later provided a root cause analysis report stating that 43 SSL certificates in total had the issue, with the remaining 31 already expired or revoked at the time of discovery. In the remediation, Id enTrust updated its SSL certificate profiles so that renewal requests would mint the Locality, State, and Country from the organization’s main address in all cases. The bug was resolved as FIXED, and a later comment indicated remediation was complete.
- IdenTrust discovered an address-field discrepancy in some SSL certificates during an internal systems review and began investigating.
- IdenTrust implemented a permanent production system fix to ensure renewal requests mint address data from the organization’s main address.
- IdenTrust Services, LLC — IdenTrust disclosed the incident, described discovery during an internal review, stated issuance was stopped, and reported revocation of the 12 affected certificates plus the remediation steps and timeline.
- Fastly representative — Fastly asked whether Id enTrust would perform and report a root cause analysis and requested a complete timeline and learnings.
- IdenTrust Services, LLC — IdenTrust said it would provide a further investigation analysis update early next week.
- IdenTrust Services, LLC — IdenTrust posted a Root Cause Analysis Report describing the cause, the configuration change implemented on February 5, 2019, and the total count of certificates affected (43), concluding no further activity was scheduled.
- Fastly representative — Fastly commented that it appears all questions were answered and remediation is complete.