Telia: Ambiguity on KeyUsage with ECC public key
Telia reported a problem involving ECDSA certificates whose Key Usage (KU) values combined “key encipherment” and “data encryption,” which Telia stated does not make sense and should be treated as misissuance. Telia said it became aware of the issue when it received an email from Secom (Tadahiko Ito) about five possibly incorrect certificates with improper KU values, and Telia verified the five certificates. Telia started a revocation process for two still-active certificates and investigated why the problem existed; Telia found the error had been fixed in 2018 but that these older certificates were undetected because Telia’s zlint setup did not log this KU combination as a problem. Telia stated it created and used a better scanner than zlint, scanned all active Telia SSL certificates, and found three additional similar problem certificates, then started revocation for them as well. Telia reported that the problematic certificates were revoked, and Mozilla later indicated the remediation was complete. The bug was resolved as FIXED.
- Telia received an email from Secom identifying five possibly incorrect ECDSA certificates with improper Key Usage values and verified them.
- Telia investigated the cause, identified that the issue was not detected by its zlint configuration, and began remediation including revocation and scanner improvements.
- Telia scanned all active certificates with a new scanner, found additional problematic certificates, and initiated revocation for them.
- Telia reported that all problematic certificates listed in the case were revoked.
- Mozilla/participants stated that questions were answered and remediation was complete.
- Teliasonera representative — Telia described the KU issue, verified five certificates from Secom’s email, started revocation for two active certificates, investigated detection gaps with zlint, created a better scanner, scanned active certificates, found three more problematic certificates, and stated Telia stopped issuing this KU combination in 2018.
- Teliasonera representative — Telia stated that all problematic certificates listed above are revoked.
- Community commenter — Ryan Sleevi noted it was an old issue, referenced an IETF document in the editor’s queue, and pointed to a zlint issue as the resolution pending finalization.
- Fastly representative — Wayne Thayer stated it appears all questions have been answered and remediation is complete.