DigiCert: P-384, ecdsa-with-SHA512 certificates (Mozilla policy section 5.1)
This case concerns DigiCert certificates that were reported as violating Mozilla policy section 5.1 due to use of a P-384 sub-CA key with the ecdsa-with-SHA512 signature algorithm. The certificates were reported to the mozilla.dev.security.policy mailing list with crt.sh links and certificate details. DigiCert acknowledged the report and said it was investigating, and then provided an incident report describing how it became aware of the issue via a post on the mozilla dev security forum and a notification from Wayne Thayer via this Bugzilla bug. DigiCert implemented a system block on February 13, 2019 and stated it had blocked issuance of these types of certificates. DigiCert reported that it had a total of 94 certificates (including 8 valid and 86 pre-certificates) with first issue date of November 11, 2017 and last issue date of February 6, 2019. Later in the thread, DigiCert provided additional scan results and crt.sh links, and Wayne Thayer stated that questions had been answered and remediation was complete. The bug is marked RESOLVED with resolution FIXED.
- DigiCert acknowledged a Bugzilla report about P-384 / ecdsa-with-SHA512 certificates and began investigating.
- DigiCert implemented a system block and blocked issuance of the reported certificate types.
- The reporter indicated remediation was complete.
- Fastly representative — Reported a list of certificates (with crt.sh URLs and details) said to violate Mozilla policy section 5.1 due to P-384 and ecdsa-with-SHA512.
- DigiCert — Acknowledged the request for an incident report and said DigiCert would post an update after investigating.
- DigiCert — Posted an incident report describing awareness of the issue, actions taken (including a system block), and counts/timing of problematic certificates.
- DigiCert — Provided additional scan results (SHA-1 thumbprints) for the problematic certificates.
- Community commenter — Asked about difficulty finding some of the reported thumbprints and referenced a crt.sh query URL.
- DigiCert — Said she would post the actual crt.sh links and follow up.
- DigiCert — Provided crt.sh links corresponding to the additional thumbprints.
- Fastly representative — Stated that questions had been answered and remediation was complete.