Telia: Disallowed curve (P-521) in leaf certificate
This case reports that Telia issued a leaf certificate using an ECDSA key on the P-521 curve, which Telia stated is disallowed by Mozilla’s security policy that permits only P-256 and P-384. Telia said it became aware of the problem from an incident report email from Ben Wilson on 29 Jan 2021, after its ACME solution created the certificate on 25 Jan 2021. Telia reported that its lint checker found the erroneous certificate and that the Telia PKI team evaluated the incident, confirmed corrective actions were required, and investigated similar cases (none were found). Telia stated it revoked the illegal certificate and enhanced its lint alarming rules, and it initiated a bug fix for the ACME server root cause. In later comments, Telia stated it fixed the ACME Server component so it correctly rejects CSRs that request P-521, logging an error when CSR checks fail, and that process improvements for lint error handling were put in place. Mozilla indicated the bug could be closed and scheduled closure unless additional issues were discussed; the bug is marked RESOLVED with resolution FIXED.
- Telia created a certificate using its ACME solution that used the P-521 curve.
- Telia’s lint checker identified the erroneous P-521 certificate and sent an incident alarm; Telia received an incident report email from Ben Wilson.
- Telia evaluated the incident, revoked the illegal certificate, enhanced lint alarming rules, and initiated a fix for the ACME server.
- Telia reported the ACME Server fix was completed to reject P-521 CSRs and that related process improvements were in place.
- Sectigo — Rob Stradling pointed out that crt.sh showed an ECDSA key on P-521 while Mozilla’s policy permits only P-256 and P-384, and referenced a related discussion thread.
- Teliasonera representative — Pekka Lahtiharju described how Telia became aware of the issue, provided a timeline of Telia’s investigation, revocation, lint/alarming improvements, and ACME server fix work, and stated Telia had re-linted active Telia SSL certificates.
- Teliasonera representative — Pekka Lahtiharju stated Telia fixed the ACME Server bug so it rejects CSRs that use P-521 and added process improvements for lint error handling, and said Telia was ready to close the bug.
- Mozilla representative — Ben Wilson said the bug could be closed and scheduled closure on or about 5-Feb-2021 unless additional issues were discussed.