← D-TRUST cases
Bugzilla #1610303
Certificate Problem Report
D-TRUST: Issuance of non-conformant SSL certificate
RESOLVED
FIXED
D-TRUST
AI Summary
D-TRUST reported the issuance of a non-conformant SSL certificate on January 20, 2020, due to a misconfiguration. The certificate was revoked shortly after issuance, and D-TRUST promptly halted production to investigate the issue. They corrected the configuration and implemented measures to prevent future occurrences, including limiting the number of configuration changes and enhancing their pre-linting system. The final report indicated that the corrective actions were completed successfully, and the case was resolved.
Chronology
- Certificate with S/MIME attributes issued
- Certificate revoked by customer
- Production halted for investigation
- Configuration corrected
- Production restarted
- All corrective actions completed
Participants
Enrico Entschew
wthayer@fastly.com
ryan.sleevi@gmail.com
bwilson@mozilla.com
External References
Similar Local Cases
D-TRUST: Private Key Disclosed by Customer as Part of CSR
D-TRUST: Wrong key usage (Key Agreement)
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
D-TRUST: Wrong key usage (Key Encipherment)
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
D-Trust: Notice to affected Subscriber and person filing CPR not sent within 24 hours
D-TRUST: syntax error in one tls certificate
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates