Izenpe incident: certificate issued for an internal domain due to CSR mix-up
Izenpe reported that one TLS certificate was misissued because the operator used the CSR for an internal CA request when issuing a certificate for an external domain. The problem was first detected by Izenpe’s internal detection system on 2020-07-06, and the affected certificate was revoked shortly after. Izenpe said the root cause was a mismatch between the CSR and the application form, combined with a manual contingency path that allowed requests outside the web application. Mozilla reviewers asked for more detail about the validation flow, CAA checking, and the controls that would prevent recurrence. Izenpe later said it removed the alternative request path, enabled additional subject/SAN checks, revoked four certificates that had been validated using the manual path, and integrated the web application with the PKI system so issuance is now automated and the CSR is rebuilt from validated data. The bug was resolved as FIXED, and Mozilla later indicated the matter appeared adequately addressed.
- Izenpe detected a certificate issued for an internal domain and revoked the affected certificate.
- Izenpe stopped allowing certificate requests through the manual alternative path and required use of the web application.
- Izenpe re-enabled subject/SAN checks in its PKI software.
- Izenpe revoked four certificates that had been processed through the manual validation path.
- Izenpe said the web application and PKI system integration was in production.
- Izenpe S.A. — Izenpe opened the bug and reported that internal monitoring found one misissued certificate, which had already been revoked.
- Community commenter — Mozilla asked for a more complete incident report, including how the failure happened and what controls would prevent unvalidated issuance.
- Izenpe S.A. — Izenpe described a manual contingency process, listed four affected certificates, and said it had required customers to use the web application.
- Izenpe S.A. — Izenpe explained the validation methods used for the four certificates and said the misissued certificate resulted from using the wrong CSR.
- Izenpe S.A. — Izenpe said it had used Google dig for CAA lookups, acknowledged that this was third-party software, and revoked the four affected certificates.
- Izenpe S.A. — Izenpe said the integration with the PKI system was in production and that validations were now automated.
- Mozilla representative — Mozilla said it was inclined to close the matter as adequately addressed.