← Buypass cases
Bugzilla #1595113
Certificate Problem Report
Buypass: Intermediate certificates not listed in audit reports
RESOLVED
FIXED
Buypass
AI Summary
Buypass reported an incident involving eight intermediate certificates that were not included in their audit reports. The issue was first identified through a discussion on mozilla.dev.security.policy. Following investigations, Buypass decided to revoke six of the certificates, while two remained under further investigation due to their extensive use. The situation highlighted a misunderstanding of the relationship between intermediate certificates and their associated issuing CAs regarding audit requirements.
Chronology
- Issue identified in discussion on mozilla.dev.security.policy
- Revocation of six intermediate certificates initiated
- Revocation date set for the last two intermediate certificates
Participants
Mads Henriksveen
Wayne Thayer
Ryan Sleevi
External References
Similar Local Cases
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs
Buypass: Insufficient Serial Number Entropy
Buypass: intermediate certificates not revoked within BR time period
Buypass: PSD2 QWAC with RSA modulus not divisible by 8
Buypass: Illegal Business Category in a PSD2 QWAC
Buypass: Failure to revoke PSD2 QWACs within mandated 5 days
Asseco DS / Certum: Intermediate CA certificates not listed in audit report
Buypass: Domain validation method using externally operated DNS tools