Entrust: Incorrect keyUsage for ECC certificate
On 25 September 2020, Entrust’s compliance team discovered via post-issuance linting that an ECC SSL certificate had been issued with a keyUsage value of keyEncipherment. Entrust stated that it interpreted the CA/B Baseline Requirements and RFC 5480 such that ECC SSL subscriber certificates should not include keyEncipherment, and that the certificate should have used an allowed combination such as digitalSignature, nonRepudiation, and/or keyAgreement. Entrust said the issue occurred when a Retail OV ECC SSL certificate request was not blocked and was routed to a CA configured to issue subscriber certificates with RSA keys, resulting in the incorrect keyUsage being signed. Entrust initiated revocation for the affected certificate after receiving a subscriber revocation request at 25 September 2020 8:50 UTC, and it began investigating the issue. Entrust later reported remediation steps: updating zlint to the latest version and updating pre-issuance linting code so that incorrect keyUsage would produce an error and stop certificate issuance. Entrust stated that effective 23 October 2020, zlint was updated and pre-issuance linting would block future incorrect keyUsage, and the bug was set to be closed on or about 30 October 2020 unless further issues were discussed. The bug’s resolution is FIXED and the current status is RESOLVED.
- Entrust issued an ECC SSL certificate with keyUsage set to keyEncipherment and later revoked it after a subscriber revocation request.
- Entrust updated zlint and updated pre-issuance linting code to block future issuance when keyUsage is incorrect.
- Entrust representative — Entrust reported that post-issuance linting found an ECC SSL certificate with keyUsage=keyEncipherment, described the suspected routing/enrollment path that allowed the request through, and stated a revocation was performed.
- Community commenter — Ryan asked Entrust to factor in related prior bugs/discussions into the timeline.
- Entrust representative — Bruce responded that the referenced issues did not apply to Entrust’s root cause as described, and said the current issue was a bug in enrollment software that sent an ECC key request to an RSA-configured CA.
- Community commenter — Ryan asked for a remediation timeline and discussed how controls should be evaluated across CAs.
- Entrust representative — Bruce stated remediation would include correcting the Retail ECC handling, updating zlint, and updating code so pre-issuance linting would error and stop issuance; he gave a remediation target no later than 30 October 2020.
- Entrust representative — Bruce reported that zlint was updated effective 23 October 2020 and pre-issuance linting code would stop issuance on incorrect keyUsage, stating actions were completed.
- Mozilla representative — Mozilla indicated it would close the bug on or about 30-Oct-2020 unless other issues remained.