← DarkMatter LLC cases
Bugzilla #1576283
Certificate Problem Report
QuoVadis: N/A in EV serialNumber field
RESOLVED
FIXED
DarkMatter LLC
AI Summary
QuoVadis identified an issue where 32 certificates were issued with 'N/A' in the EV serialNumber field, affecting a government entity. The problem was reported by a security researcher, prompting QuoVadis to initiate a staggered revocation process due to the critical nature of the certificates involved. All affected certificates were successfully revoked by August 23, 2019. QuoVadis has since implemented measures to prevent similar issues in the future, including the introduction of filters for the EV serialNumber field.
Chronology
- QuoVadis notified by a security researcher about the issue.
- All 32 certificates have been revoked.
- New filters for the EV serialNumber field implemented in production.
Participants
Stephen Davidson
Wayne Thayer
Ryan Sleevi
External References
Similar Local Cases
QuoVadis: EV JOI Issue
QuoVadis: LLB insufficient Serial Number Entropy
QuoVadis: Incorrect keyUsage for ECC certificate
QuoVadis: EV serialNumber with "none"
QuoVadis: BR Error - san dns name starts with period
QuoVadis: Failure to revoke certificates with compromised private keys
QuoVadis: use of Organisationidentifier field in EV (Pre CABF Ballot SC17)
QuoVadis: Incorrect OCSP Delegated Responder Certificate