QuoVadis: Incorrect keyUsage for ECC certificate
QuoVadis reported that it had issued a small number of similar ECC TLS certificates in 2019 with an incorrect keyUsage value of keyEncipherment. QuoVadis said it became aware of the issue by monitoring Bugzilla filings and noting an Entrust bug related to keyEncipherment keyUsage in ECC certificates, then identified similar certificates it had issued in 2019. After investigation, QuoVadis confirmed its CA policies, identified nine valid problem certificates, and informed subscribers with revocation scheduled by Oct 1, 20:00 UTC at the latest. QuoVadis stated it stopped issuing such certificates in 2019 and confirmed that existing certificate profiles do not allow the issue. On Oct 1, 2020, QuoVadis confirmed that the nine affected certificates had been revoked. QuoVadis also described a postmortem and remediation steps, including a correction to certificate profiles, discussion of why revocation was not done for then-existing certificates, and plans for periodic review of zLint messages as part of compliance/internal audit activities. The bug was marked RESOLVED with resolution FIXED.
- QuoVadis issued ECC TLS certificates with keyUsage set to keyEncipherment during 2019 (between February and November).
- QuoVadis stopped issuing certificates with this problem in 2019.
- QuoVadis identified similar certificates it had issued in 2019 and began an investigation.
- QuoVadis confirmed the nine affected certificates had been revoked.
- DigiCert — QuoVadis reported that it identified a small number of similar certificates issued in 2019 with keyEncipherment keyUsage for ECC, and said it would investigate, confirm revocation, and provide root cause and remediation details.
- DigiCert — QuoVadis provided a timeline, stated it stopped issuing such certificates in 2019, identified nine valid problem certificates, and said subscribers were informed with revocation scheduled by Oct 1, 20:00 UTC.
- DigiCert — QuoVadis confirmed that the nine affected certificates had been revoked and said further updates on cause and remediation would follow.
- DigiCert — QuoVadis explained how the mistakes were introduced and why revocation was not done for then-existing certificates, and described remediation steps including profile review and periodic review of zLint messages.
- Community commenter — Ryan Sleevi stated he had no follow-up questions and praised the proactive incident reporting and remediation context.
- Mozilla representative — Mozilla said it would schedule the bug to be closed on 30-October-2020 unless additional discussion was needed.