Buypass: PSD2 QWAC with RSA modulus not divisible by 8
Buypass reported an incident involving a PSD2 Qualified Website Authentication Certificate (QWAC) that had an RSA modulus not divisible by 8. The issue was first identified on July 17, 2020, when Digicert notified Buypass. In response, Buypass temporarily halted the issuance of manually issued certificates and conducted an analysis of their active certificates, finding no other affected instances. The problematic certificate was revoked on July 20, 2020, and Buypass implemented additional controls to prevent future occurrences. The incident was resolved with no further certificates issued with the same issue.
- Digicert notified Buypass about the problem.
- The affected certificate was revoked.