SSL.com: P-384 curve / ecdsa-with-SHA256 certificates
SSL.com disclosed that it had issued a limited number of ECDSA certificates using a curve-hash pair that is no longer allowed by the Mozilla Root Store Policy. The issue specifically involved certificates issued with the P-384 curve / ecdsa-with-SHA256 pair, which the incident report states is not permitted under Mozilla Root Store Policy section 5.1 (which allows P-384 with SHA-384). SSL.com said it became aware of the problem during a manual review of certificates that were going to be issued on 25 February 2019, and that the investigation found additional certificates had been issued using the same illegal curve-hash pair, including several CA certificates. SSL.com suspended ECDSA issuance, contacted Mozilla, and began remediation, including reviewing Mozilla technical requirements and implementing linters to improve pre-issuance and post-issuance auditing. SSL.com modified production CA configuration to prevent future issuance with these parameters, revoked misissued end-user certificates, and also decided to revoke associated CAs (including those created before the policy change) while resuming ECDSA issuance after fixing certificate profiles. The bug was resolved as FIXED, and a later comment stated that remediation was completed and there appeared to be no questions on the incident report.
- Mozilla Root Store Policy version 2.4 was published, limiting allowed ECDSA curve-hash pairs.
- SSL.com identified that some certificates being reviewed for issuance used an illegal ECDSA curve-hash pair (P-384 with SHA-256).
- SSL.com suspended ECDSA issuance and began remediation, contacting Mozilla and implementing policy requirement linters.
- SSL.com updated production CA configurations, revoked misissued end-user certificates, revoked associated CAs, and resumed ECDSA issuance.
- Fastly representative — Posted an incident report describing SSL.com’s issuance of P-384/ecdsa-with-SHA256 certificates, the discovery during internal review, and the remediation steps including suspension, linters, configuration changes, and revocations.
- Fastly representative — Commented that all remediation had been completed and that there appeared to be no questions on the incident report.