Sectigo: Certificates with RSA keys where modulus is not divisible by 8
This case concerns Sectigo certificates whose RSA key modulus size in bits was not divisible by 8, which Sectigo identified as non-compliant with the relevant requirement. Sectigo first became aware of additional affected certificates after an email from Jeremy (Digicert) on 2020-07-17, and Sectigo assessed the list and found 32 certificates total, including two certificates that were not on the earlier list from bug 1518553. Sectigo revoked the two missed certificates on 2020-07-17. Sectigo later re-ran scans over its issued-certificate corpus and identified an additional ten certificates that were not on the earlier list; Sectigo stated these were already being processed for revocation and would be revoked on or before 2020-08-02 6am UTC. Sectigo also described that its earlier reporting was based on CT log data (via crt.sh) and that some older certificates may not have appeared in CT logs, leading to missed detection until Jeremy’s report. The bug was marked RESOLVED with resolution FIXED, and a later bug (1725041) was marked as a duplicate of this bug.
- Bug 1518553 was opened covering issuance of certificates with the p521 curve and RSA keys of incorrect size.
- Sectigo received a report identifying certificates with incorrect RSA key sizes and revoked two missed certificates.
- Sectigo stated it would revoke an additional set of non-compliant certificates by this deadline.
- Sectigo — Nick France explained how Sectigo became aware of the issue, identified two certificates missed from the earlier list, and stated those certificates were revoked.
- Community commenter — Ryan Sleevi asked for more thorough analysis and questioned whether Sectigo had institutionalized lessons from other CA incidents.
- Sectigo — Nick France said a more detailed update would be posted soon with expanded sections 6 and 7.
- Sectigo — Nick France expanded on how the reporting missed certificates, described additional certificates found via a scan, and stated they were being processed for revocation.
- Sectigo — Rob Stradling shared a spreadsheet of scan results and said Sectigo was confirming externally-operated CAs’ compliance, awaiting responses from Apple and D-TRUST.
- Sectigo — Rob Stradling stated Apple had not issued non-compliant certificates and expected a response from D-TRUST.
- Sectigo — Rob Stradling stated D-TRUST had not issued any certificates that fell foul of the modulus-divisible-by-8 requirement.
- Sectigo — Rob Stradling asked whether the bug could be closed.
- Mozilla representative — Mozilla marked Bug 1725041 as a duplicate of this bug.