DigiCert: Key Size Not Divisible By 8
DigiCert reported a compliance issue involving RSA keys whose key sizes were not divisible by 8. DigiCert said it became aware of the problem after reading a DFN-PKI Bugzilla report (Bug 1651132) and then running its own compliance analytics scan, which found roughly 290 certificates across various CAs with bad key sizes that had not been revoked; DigiCert identified 24 such certificates, with 22 already revoked. DigiCert stated that the remaining two certificates were discovered during a later scan and were scheduled to be revoked within the five-day timeline, and that the last two were logged to CCADB and revoked. DigiCert also described implementing a CA-side block for RSA keys not divisible by 8 starting in Feb 2019 and said it would not issue new certificates in scope of this bug. Mozilla indicated it would close the bug on or about 28-July-2020 unless further issues or questions were raised. The bug was resolved as FIXED.
- DigiCert implemented code blocking RSA keys not divisible by 8 at the CA.
- DigiCert scanned its issued certificates and identified DigiCert certificates with key sizes not divisible by 8.
- DigiCert revoked 22 certificates identified as affected.
- DigiCert found two additional affected certificates and scheduled their revocation.
- DigiCert confirmed the last two certificates were logged to CCADB and revoked.
- DigiCert — DigiCert explained it scanned after reading Bug 1651132, found 24 affected DigiCert certificates (22 already revoked), and said the last two would be revoked within the five-day timeline.
- DigiCert — DigiCert confirmed the last two certificates were logged to CCADB and revoked, and asked if anything was needed before closing the bug.
- Mozilla representative — Mozilla stated it would schedule the bug for closure on or about 28-July-2020 unless further issues or questions were raised.
- Community commenter — Ryan Sleevi expressed concern about the explanation for missing past controls and asked for careful examination of past incidents, while noting closure as-is might be acceptable.