eMudhra: emSign CA ECC test certificate misissuance (incorrect Key Usage)
The case reports that eMudhra’s emSign CA issued SSL/TLS certificates using ECC that contained an incorrect Key Usage value (keyEncipherment). The CA stated it became aware of the problem through a report received on 10-Sep-2020 09:19 (Indian Time). The CA said the impacted certificates were limited to test certificates used for its test websites (and other test certificates that were part of revoked and expired URLs), and that it flagged the incident as non-critical with no impact to external customers. In response, the CA made system changes to correct the certificate issuance configuration, restarted issuance of new test certificates, and completed independent lint tests. The CA also completed revocations and stated that misissuance analysis was completed, with the problematic certificates first issued between 21-Aug-2020 and last issued on 28-Aug-2020 (24 problematic certificates total, including 20 already revoked/expired prior to notice, and 4 active that were revoked). Mozilla indicated it intended to close the incident unless there were further questions, and the CA provided additional explanation addressing concerns about the incident report’s detail. The bug is marked RESOLVED with resolution FIXED.
- eMudhra configured its certificate issuance procedure for generating test certificates for test URLs.
- eMudhra issued the first set of ECC test certificates.
- eMudhra revoked test certificates as part of CT log server configuration changes.
- eMudhra received a problem report about the incorrect Key Usage in ECC test certificates and began analysis.
- eMudhra flagged the incident and made system changes to correct the issuance configuration.
- eMudhra completed issuance and verification of new test certificates and completed test URL configuration.
- eMudhra completed incident analysis review.
- eMudhra completed revocations for the problematic certificates.
- eMudhra completed misissuance analysis.
- Emudhra representative — Vijay Kumar disclosed that ECC SSL/TLS test certificates were issued with Key Usage set to keyEncipherment, described the CA’s timeline, and listed CT links for the problematic certificates.
- Mozilla representative — Ben Wilson thanked the CA for the disclosure and said he intended to close the incident on or about 9-Oct-2020 unless questions remained.
- Community commenter — Ryan Sleevi requested more detailed incident-report information, questioning the sufficiency of the explanation and the framing of impact as internal-only.
- Mozilla representative — Ben Wilson asked Vijay to respond to Ryan’s questions and comments.
- Emudhra representative — Vijay responded with additional explanation, stating the issue was due to misconfiguration/oversight for test certificates and that procedures were updated with additional verification and linting coverage.
- Mozilla representative — Ben Wilson pushed closure out by another week, setting a tentative closure date of 16-Oct-2020.