Telia: Misissued certificate - Invalid OU value "-"
Telia reported that it discovered nine invalid certificates during a mass lint scan of its SSL certificates on February 8, 2019. The certificates were found in multiple error categories, including three certificates with an invalid OU value "-" (e_subject_contains_noninformational_value). Telia said it performed preliminary analysis and determined the certificates should be revoked within 24 hours and must be revoked within 5 days, and it revoked the affected certificates on February 8, 2019. Telia later stated that it fixed the underlying OU verification code bug in Summer 2018 and that the issue could not be reproduced in its current systems. In response to questions about recurrence, Telia clarified that it implemented a pre-check around July 2018 to prevent enrollment for the forbidden values, and that post-issuance linting is used to find previously unknown issues only. The bug was marked RESOLVED with resolution FIXED, and a later comment stated that remediation appeared to be completed.
- Telia performed a mass lint scan of its SSL certificates and discovered nine invalid certificates, including three with an invalid OU value "-".
- Telia revoked the affected certificates after preliminary analysis.
- Telia completed quick analysis and began root cause analysis of the OU verification issue.
- A comment indicated remediation had been completed.
- Teliasonera representative — Reported that Telia’s mass lint scan found nine invalid certificates, including three with invalid OU value "-", and described the incident and Telia’s response steps.
- Fastly representative — Asked whether Telia had not prevented recurrence because linting is done post-issuance, and how Telia would prevent the issue from happening again.
- Teliasonera representative — Clarified that a pre-check implemented around July 2018 prevents enrollment for the forbidden OU values, and that only certificates created before that timestamp may have the issue.
- Tds representative — Posted links to crt.sh queries for the certificates referenced in the thread.
- Mozilla representative — Corrected the bug type to a task.
- Fastly representative — Commented that remediation has been completed.