SK ID Solutions: ALV failures on intermediate certificates
This case was opened because SK ID Solutions reported in response to Mozilla’s January 2020 CA Communication survey that it had no audit issues with its intermediate certificates identified by CCADB, but Audit Letter Validation (ALV) reported FAIL results for four specific intermediate certificates under EID-SK 2011 and ESTEID-SK 2011. The ALV results included issues such as missing certificates from the audit statement and mismatches in Extended Key Usage/derived trust bits for some certificates, and Mozilla asked the CA to follow the “When ALV returns FAIL” remediation guidance. SK ID Solutions stated that it was investigating and later said it would inform Mozilla about results and an action plan. SK then informed Mozilla that it would revoke the four intermediate certificates not provided in the audit statement, and subsequently reported that it revoked EID-SK 2011 and ESTEID-SK 2011 certificates not included in the AVL on 27.02.2020. SK also provided a link to a new CRL containing the revoked intermediate certificates, and later noted that the missing “doppelganger” certificates were revoked and marked as “Ready to Add” to OneCRL. The bug is marked RESOLVED with resolution FIXED.
- Mozilla’s ALV reported FAIL results for four EID-SK 2011/ESTEID-SK 2011 intermediate certificates that were not reflected in the audit statement.
- SK ID Solutions announced it would revoke the four intermediate certificates not provided in the audit statement.
- SK ID Solutions revoked the four intermediate certificates and published a CRL containing the revoked intermediates.
- SK ID Solutions reported the missing doppelganger certificates were revoked and marked as “Ready to Add” to OneCRL.
- Mozilla representative — Filed the bug after ALV reported FAILs for multiple EID-SK 2011 and ESTEID-SK 2011 intermediate certificates and cited the ALV remediation guidance.
- Mozilla representative — Provided details from ALV, including Extended Key Usage/derived trust bits observations and recommendations that non-audited certificate versions be revoked.
- Community commenter — Asked whether no one at skidsolutions.eu had a Bugzilla account set up to assign the bug.
- SK ID Solutions AS — Explained that the CA-s were audited until valid and stated SK was not able to revoke the intermediates because they were valid and audited by SK’s conformity assessment body.
- Mozilla representative — Requested the audit statements listing the four certs as in scope and pointed to Mozilla’s “Acceptable remediation” requirements.
- SK ID Solutions AS — Said SK was investigating issuance of ESTEID-SK 2011 and EID-SK 2011 certificates and would provide results and an action plan.
- SK ID Solutions AS — Informed Mozilla that SK would revoke EID-SK 2011 and ESTEID-SK 2011 certificates (4 total) not provided in the audit statement on 27.02.2020.
- SK ID Solutions AS — Reported that SK revoked the EID-SK 2011 and ESTEID-SK 2011 certificates not included in the AVL on 27.02.2020 and provided a CRL link.
- Mozilla representative — Confirmed that the missing doppelganger certificates had been revoked and marked as “Ready to Add” to OneCRL.