E-Tugra: Invalid DER results in failure to comply with RFC 5280 (country name length limit)
This case concerns E-Tugra certificates that were incompatible with RFC 5280 due to invalid country name encoding/character data and an overlong country name. The issue was identified after a prior Mozilla CA Program incident report in Bug 1462797, and Ryan Sleevi noted that the specific certificate in this bug was issued on 2018-09-12 and was not revoked at the time of the initial report. Davut Tokgöz stated they were investigating the miscompliance and later provided an incident report describing how E-Tugra became aware of the problem via Bugzilla and how they tested historical certificates. E-Tugra reported that it rebuilt its RFC 5280 compliance controls in January 2019, then tested certificates and discovered additional certificates issued incompatible with RFC 5280, which were replaced and revoked. E-Tugra also stated that as of September 30, no more certificates were found in its systems with the problem, and as of January 31 no more certificates would be produced with these problems. The thread concludes with a comment indicating that remediation is complete and that questions were answered.
- E-Tugra issued a certificate later identified as incompatible with RFC 5280 due to country name issues.
- E-Tugra reported rebuilding RFC 5280 compliance controls and completing remediation for the related control issues.
- E-Tugra reported finding no further certificates in its systems with the RFC 5280 incompatibility.
- E-Tugra indicated remediation was complete and that questions had been answered.
- Community commenter — Reported that E-Tugra issued a certificate with an invalid, overlong country name per RFC 5280 and noted it was not revoked at the time.
- Community commenter — Asked why the certificate was not previously detected and what steps E-Tugra was taking to examine historical issuance against current controls.
- E-Tugra — Said he was investigating the miscompliance and would provide a report soon.
- E-Tugra — Provided an incident report describing awareness, testing of certificates, replacement/revocation, and remediation steps (including an Excel report link).
- Fastly representative — Requested an update explaining how certificates would not be missed in future investigations beyond the specific incident.
- E-Tugra — Provided an updated report including additional internal procedure instructions to avoid missing similar certificates.
- Fastly representative — Indicated it appears all questions were answered and remediation is complete.