← certSIGN cases
Bugzilla #1551375
Certificate Misissuance
certSIGN: "Some-State" in stateOrProvinceName
RESOLVED
FIXED
certSIGN
AI Summary
certSIGN issued a certificate with a stateOrProvinceName of "Some-State", a default value in OpenSSL CSRs, indicating a lack of validation. The certificate was revoked the day after its discovery on May 11, 2019. An incident report was requested, detailing the timeline of events and the measures taken to prevent future occurrences. certSIGN acknowledged the issue and implemented technical controls to check for default values in the stateOrProvinceName field. The incident highlighted the need for improved validation processes within the CA's operations.
Chronology
- Problem reported via email; certificate identified and revoked.
- Bug raised on Bugzilla regarding the issue.
- Incident report submitted by certSIGN.
- Update to CSR checker deployed to production.
Participants
Wayne Thayer
Cristian Garabet
Ryan Sleevi
External References
Similar Local Cases
DigiCert: "Some-State" in stateOrProvinceName
SECOM: Failure to disclose Unconstrained Intermediate within 7 Days
SwissSign: "Some-State" in stateOrProvinceName
SECOM: "Default City" in Subject:localityName
NetLock: CN not in SAN
E-Tugra: Invalid DER results in failure to comply with RFC 5280 - Violating string length limit
Telia: "Some-State" in stateOrProvinceName
Kamu SM: "Some-State" in stateOrProvinceName