TrustCor: Incorrect CA-Issuers URI
TrustCor reported a compliance issue discovered during its post-issuance CT log monitoring process: two certificates contained an incorrect URI value in the CA Issuers portion of the authorityInformationAccess extension. TrustCor became aware of the issue on 2019-07-22 11:36:00 UTC, suspended certificate issuance for the ECA-1 CA hierarchy pending investigation, and completed revocation of the two affected certificates by 2019-07-22 11:42:45 UTC. TrustCor stated the incorrect value was set to the Basic Secure Site CA certificate instead of the ECA-1 External CA certificate, and that the error was missed because its profile QA tool only verified that the CA Issuers URI pointed to a valid TrustCor CA certificate, while test vs. production URI domains differed. TrustCor completed an emergency change order to correct the ECA-1 internal example certificate profile values on testing and production, and testing issuance then produced corrected certificates. TrustCor also reported that software changes to its certificate sanity checking process were completed, requiring that any CA-Issuers URI in a profile match a valid TrustCor CA certificate with an exact Subject DN and corresponding public/private key relationship. The bug was resolved as FIXED, with later comments indicating remediation was complete and questions were answered.
- TrustCor identified two certificates with an incorrect CA-Issuers URI, suspended ECA-1 issuance, and revoked the affected certificates.
- TrustCor completed an emergency change order to correct ECA-1 internal example certificate profile values and resumed corrected issuance.
- TrustCor reported completion of software changes to certificate sanity checking to prevent similar CA-Issuers URI misconfigurations.
- TrustCor concluded remediation was sufficient after no further feedback and reported remediation complete.
- Fastly representative — Wayne Thayer posted TrustCor’s incident report describing discovery via CT log monitoring, suspension of ECA-1 issuance, revocation of two certificates, profile correction, and remediation steps.
- Trustcorsystems representative — Neil Dunbar stated the certificate sanity checking software improvements were complete and described the pre-certificate signing checks now enforced before production issuance.
- Trustcorsystems representative — Neil Dunbar asked for feedback on whether the remediations were sufficient and indicated an intent to close the bug if no comments were posted.
- Trustcorsystems representative — Neil Dunbar tentatively concluded the remediations were sufficient after receiving no further input.
- Fastly representative — Wayne Thayer commented that it appeared all questions were answered and remediation was complete.