Camerfirma: Intesa Sanpaolo misissued certificates
Camerfirma reported that its Quality Control Team discovered compliance errors in certificates issued by its subCA, “Intesa Sanpaolo Organization Validation CA.” The issues included certificates that (1) “L appears to only include metadata,” (2) had serial numbers that must be 20 octets or less, and (3) were BR certificates that must not contain an rfc822Name type alternative name. Camerfirma states it communicated the misissuance to Intesa Sanpaolo’s point of contact, and Intesa Sanpaolo revoked the affected certificate(s), with Camerfirma attributing revocation delays to Intesa Sanpaolo troubles to replace the certificates and, for one issue, the number of involved certificates. Camerfirma also describes changes to its own processes and to Intesa Sanpaolo’s software, including stopping issuance for the affected cases and modifying CSR generation to avoid including an email address in the SubjectAlternativeName extension, as well as adding additional staff for detecting, resolving, and reporting incidents. In the thread, Camerfirma acknowledges that at the time it was not fully aware of the need to register bugs immediately and says it should have disclosed the incident report sooner. The bug was marked RESOLVED with resolution FIXED, and a later comment states that remediation is complete.
- Camerfirma’s Quality Control detected misissued certificates in Intesa Sanpaolo’s issuance.
- Intesa Sanpaolo installed a patch to avoid wrong serial numbers and Camerfirma reported related detection/communication.
- Intesa Sanpaolo ended revocation of the misissued certificates for the serial-number issue.
- Camerfirma detected another misissued certificate and communicated it to Intesa Sanpaolo’s point of contact.
- Intesa Sanpaolo revoked the certificate identified by Camerfirma.
- Camerfirma installed a new enrollment procedure with a pre-issuance lint check before sending pre-certificates to CT logs.
- AC Camerfirma, S.A. — Created the bug with a detailed incident description, including detection by Camerfirma’s Quality Control, communication to Intesa Sanpaolo, revocation timelines, and remediation steps.
- AC Camerfirma, S.A. — Acknowledged that Camerfirma was not fully aware of the need to register bugs immediately at the time and described staffing/process changes to avoid recurrence.
- Community commenter — Expressed concern about ensuring BR revocation timelines are honored and encouraged review of incident reports and systemic changes for timely revocation.
- Community commenter — Asked for an update.
- Community commenter — Reported emailing POCs about the issue and referenced Mozilla guidance on keeping Mozilla informed.
- AC Camerfirma, S.A. — Said Camerfirma is working to secure with Intesa Sanpaolo a procedure to ensure BR revocation timelines are honored and will apply the policy in future misissuance cases.
- AC Camerfirma, S.A. — Confirmed Intesa Sanpaolo has an active new policy to ensure BR revocation timelines are honored and that it will be applied in any eventual new case of misissuance.
- Fastly representative — Commented that it appears all questions were answered and remediation is complete.