DigiCert: Missed Underscore Certificate Revocations
This case concerns DigiCert underscore certificates that were not revoked by the January 14, 2019 deadline. A third party notified DigiCert that additional underscore certificates existed that were not revoked and were not included in DigiCert’s incident reports to Mozilla. DigiCert acknowledged the notification on February 1, 2019, concluded that some identified items were pre-certificates without a valid certificate, and confirmed that the remaining certificates were either valid certificates or already included in the incident reports. DigiCert stated it did not intend to revoke the certificates already included in the incident reports, and it began notifications to impacted customers. DigiCert ran additional reporting on February 6, 2019, revoked remaining valid underscore certificates, and revoked pre-certificates for housekeeping purposes on February 7, 2019. DigiCert attributed the missed revocations to a flaw in script logic used for the mass revocation, where the script used the order number instead of the unique serial number and missed certificates as part of the order. In later comments, DigiCert reported improvements including a comprehensive query/reporting source and improved quality control on scripts to ensure completeness and accuracy. The bug is marked RESOLVED with resolution FIXED.
- DigiCert ceased issuance of underscore certificates in light of the CAB/F discussion on this topic.
- DigiCert revoked valid underscore certificates by the SC12 ballot deadline, with an exception for 7 customer accounts that requested an extension.
- A third party notified DigiCert of additional underscore certificates that were not revoked and not included in DigiCert’s incident reports to Mozilla.
- DigiCert ran another data report to ensure it did not miss other certificates that were not revoked, and revoked remaining valid underscore certificates as reported.
- DigiCert revoked pre-certificates found with no valid certificates for housekeeping purposes.
- DigiCert — Brenda Bernal provided a detailed incident response timeline, including the script logic flaw and the revocation actions taken for missed underscore certificates.
- DigiCert — Brenda listed the pre-certificates that were revoked, with crt.sh links.
- DigiCert — Brenda asked Wayne if he needed any update or other information for the incident report.
- Fastly representative — Wayne asked for the status of DigiCert’s effort to ensure certificate data completeness across systems (data lake) to reduce future issues.
- DigiCert — Brenda responded that DigiCert has a comprehensive source for incident/ballot impact reporting and improved script quality control for completeness and accuracy.
- Fastly representative — Wayne indicated he interpreted the response as sufficient to prevent future issues and that the bug could be resolved.