Microsec: Issuance of 2 IVCP precertificates without givenName, surName, localityName fields
Microsec Ltd. reported an incident involving the issuance of two IVCP precertificates that lacked required fields: givenName, surName, and localityName. The CA became aware of the issue through discussions in the mozilla.dev.security.policy mailing list. Upon investigation, Microsec identified that the certificates were issued for internal testing and had already expired, making revocation unnecessary. The CA suspended the issuance of IVCP certificates and implemented corrective measures, including software updates to enforce compliance with certificate profile requirements. As of May 26, 2020, Microsec reactivated the IVCP profiles and resumed issuing IVCP certificates after training their Registration Officers.
- Two precertificates were issued for internal testing purposes.
- Microsec was informed about the faulty precertificates.
- Microsec activated the new CA software release in the live system.
- IVCP profiles were reactivated, allowing the issuance of IVCP certificates again.
- Fastly representative — Dr. Sandor Szoke posted the incident report detailing the compliance failure.
- Microsec representative — Microsec completed a review of the CA software for compliance with required fields.
- Microsec representative — Microsec provided a status update on the CA software development.
- Microsec representative — Microsec announced the reactivation of IVCP profiles.