HARICA: P-384,ecdsa-with-SHA256 Certificates
HARICA disclosed an incident it discovered during a detailed policy documents review in February 2019. HARICA found that it had issued intermediate CA certificates using the ECDSA P-384 key with the SHA256 hashing algorithm, which it stated violates Section 5.1 of the Mozilla Root Store Policy (effective February 28, 2017). HARICA explained that its CA software (EJBCA) was configured to inherit the Root CA key/hash combination and used the SHA256ECDSA algorithm while the key was P-384, resulting in subCA and end-entity certificates with the same pair (SHA256, P-384). After verifying the finding and creating an internal incident, HARICA disabled certificate issuance from the affected subCAs and performed a database scan, which it said found one affected end-entity certificate for a test web site and five affected intermediate CA certificates. HARICA reported that the affected CA certificates were revoked and marked accordingly in CCADB, and that remediation was complete. HARICA also stated it created a feature request with its CA software manufacturer (PrimeKey) to add validators for this rule and enforced its P-384 subCAs to use SHA384 when signing end-entity certificates, and it opened a GitHub issue with recommended language to clarify the requirement.
- HARICA discovered during a policy document review that it had issued intermediate CA certificates with an ECDSA P-384 key using SHA256 hashing, contrary to Mozilla Root Store Policy.
- HARICA disabled certificate issuance from affected subCAs and reported the incident to Mozilla, including results of a database scan and planned revocation timeline.
- HARICA revoked the affected CA certificates and marked them accordingly in CCADB (as stated in the final report).
- HARICA — Created the initial incident report, stating HARICA discovered the P-384/SHA256 issuance issue, disabled issuance from affected subCAs, scanned the database, and planned revocation by March 8, 2019.
- HARICA — Submitted a final report after revoking the affected CA certificates and marking them in CCADB.
- Fastly representative — Asked about the status of an action item to request additional validators from the CA software manufacturer.
- HARICA — Said a ticket was created for PrimeKey to check the rule, noted HARICA enforced P-384 subCAs to use SHA384 for end-entity signing, and referenced a GitHub issue to clarify the requirement.
- Fastly representative — Commented that it appears remediation is complete.
- HARICA — Provided a link for the community to follow progress on the PrimeKey feature request.