Telia incident report for invalid stateOrProvinceName value "Some-State"
Telia reported that one of its certificates contained a stateOrProvinceName value of "Some-State," which was identified as a default OpenSSL CSR value and therefore not properly validated. The bug was opened by Mozilla after the certificate was published on misissued.com, and Telia then filed an incident report describing how it first learned of the issue and what it did in response. Telia said the certificate was replaced by the customer and revoked, and that it had stopped using the ST attribute in its SSL certificates in December 2016. During the thread, Telia also reviewed additional old certificates and found more invalid ST, L, and C values, which it said were revoked or being revoked, while Mozilla repeatedly asked for clearer explanation of the validation process and remediation. The case was later discussed as focused on the original invalid ST issue, with Mozilla indicating it was inclined to close this bug and continue tracking the related L issue in another bug.
- A Telia certificate was created with an invalid stateOrProvinceName value of "Some-State".
- Telia received a report about the invalid ST value.
- The problematic certificate was replaced by the customer and revoked by Telia CA.
- Telia said it had stopped using the ST attribute in SSL certificates in December 2016.
- Mozilla said it was inclined to close this bug and focus on the related L issue in bug 1565270.
- Fastly representative — Reported that a Telia certificate with ST="Some-State" was published and requested an incident report.
- Teliasonera representative — Telia filed an incident report, said the certificate was revoked, and stated it had stopped using ST in December 2016.
- Community commenter — Questioned whether the incident report adequately explained the underlying validation failure and asked for more detail.
- Teliasonera representative — Explained that Telia manually verified L, C, and O values and that ST had been dropped from certificates.
- Teliasonera representative — Said Telia re-validated C and L values and found additional invalid certificates, including ST=FI and ST=Unknown.
- Teliasonera representative — Added four more certificates with invalid L values and said they were reported by auditors and revoked before the 5-day limit.
- Teliasonera representative — Said two-person manual reviews were in use and described a plan to automate company L checks.
- Teliasonera representative — Said the original issue was the invalid ST value and asked whether this bug could be closed while the L issue continued elsewhere.
- Mozilla representative — Said he was inclined to close this bug so Mozilla could focus on bug 1565270.