Multicert: AIA CA Issuer field pointing to PEM encoded cert
Multicert discovered that the CA certificate file linked in the Authority Information Access (AIA) of its end entity certificates was incorrectly encoded in PEM format instead of the required DER format. This issue was reported to Multicert via email on May 11, 2020. Upon confirmation of the incident, Multicert promptly replaced the CA certificate file with the correct DER encoded version in their public repository. The CA continued issuing certificates as the issue did not result in any misissuance or require revocation of end user certificates. Multicert updated its procedures to ensure future compliance with the DER format requirement.
- Multicert received a notification about the incorrect encoding of the CA certificate.
- Multicert replaced the CA certificate file with the correct DER encoded version.
- MULTICERT — Multicert reported the discovery of the PEM encoding issue and the steps taken to resolve it.
- Mozilla representative — Inquired about testing the updated procedure for publishing CA certificates in DER format.
- MULTICERT — Explained the monitoring setup for continuous compliance with the DER format requirement.
- Mozilla representative — Indicated intent to close the bug unless further comments were received.