QuoVadis: EV certificate issued with incorrect serialNumber value (“none”)
QuoVadis reported an EV certificate compliance issue after being notified by a security researcher via email to its compliance address. The reported problem was that QuoVadis issued an EV certificate with “none” in the EV serialNumber field, when the correct value should have reflected the entity information used for EV serialNumber. QuoVadis acknowledged the notification and revoked the reported certificate, and stated that the noncompliant certificate had already been replaced during its lifecycle. In the thread, Mozilla participants discussed concerns about the accuracy of the incident timeline and the correctness of the replacement certificate’s serialNumber/businessCategory handling. QuoVadis later stated that a manual search for the relevant “filler” values was caps-sensitive (“NONE”), which caused the “none” value to be missed, and that it performed a complete new search using the intended filter without finding additional problem certificates. QuoVadis also described process changes intended to reduce similar errors and requested that the bug be closed; the bug was marked RESOLVED with resolution FIXED.
- QuoVadis received notification from a security researcher about an EV serialNumber compliance problem.
- QuoVadis revoked the reported noncompliant EV certificate after acknowledging the notification.
- QuoVadis requested closure of the bug after stating the matter was resolved.
- DigiCert — Stephen Davidson explained how QuoVadis became aware of the issue, described the problematic EV serialNumber value (“none”), and stated QuoVadis revoked the reported certificate.
- Community commenter — Ryan Sleevi said the remediation appeared incomplete relative to a prior bug and questioned the dates and certificate replacement details.
- Community commenter — Paul Steinberg challenged the accuracy of the replacement certificate’s serialNumber and asked for clarification.
- DigiCert — Stephen Davidson apologized and corrected the timeline dates, stating the noncompliant certificate was issued on 6/15/2018 and replaced on 6/11/2020.
- DigiCert — Jeremy Rowley said Mozilla was kicking off a project to investigate what happened and how the issue was missed and detected.
- Community commenter — Paul Steinberg argued the replacement certificate’s serialNumber/business identifier did not align with the certificate’s organizationName and asked for revocation of the new certificate.
- Fozzie representative — George noted the leaf certificate for the new certificate was available at a specified Censys URL and not currently on crt.sh.
- DigiCert — Stephen Davidson described remediation steps, including that the prior search was caps-sensitive (“NONE”), a complete new search found no additional problem certs, and process changes to reduce future errors.
- DigiCert — QuoVadis requested the bug be closed, stating it believed the matter was properly resolved.
- Mozilla representative — Mozilla stated it intended to close the bug on or after 24-July-2020 unless further comments or questions were received.