D-TRUST: Certificate with RSA key where modulus is not divisible by 8
This case is a preliminary and then final incident report from D-TRUST about a certificate whose RSA key did not comply with the Mozilla Root Store Policy and the CA/Browser Forum Baseline Requirements. D-TRUST stated it was informed by a third party about the issue via D-TRUST’s Incident Report Mechanism. D-TRUST reported that the affected certificate was issued on 2019-02-14 and that it was issued through D-TRUST’s retail customer application processing system, which D-TRUST said was shut down for good on 2019-07-19. D-TRUST said it revoked the affected certificate within the timeframe specified by BR and performed analysis across all databases to ensure no valid certificate exists with an RSA key size not divisible by 8. D-TRUST also stated it re-examined technical measures to prevent issuance of such TLS certificates and adapted specification documents so future analyses must be carried out on all TLS databases containing at least one still-valid TLS certificate. Mozilla indicated it intended to close the matter on 10-Mar-2021, and the bug is marked RESOLVED with resolution FIXED.
- D-TRUST issued a TLS certificate whose RSA key modulus was not divisible by 8.
- D-TRUST shut down its retail-customer application processing system for good.
- D-TRUST began investigating the reported non-compliant certificate and its issuance circumstances.
- D-TRUST revoked the affected certificate.
- D-TRUST published its final incident report after completing thorough analysis.
- Mozilla indicated it intended to close the matter.
- Bdr representative — Opened a preliminary incident report stating D-TRUST was informed via its Incident Report Mechanism that it had issued a certificate with an RSA key not complying with Mozilla Root Store Policy and CA/Browser Forum Baseline Requirements, and provided an investigation timeline and planned revocation.
- Thisisntrocket representative — Asked for clarification on whether D-TRUST had checked its current valid certificate corpus or whether it would only avoid signing new certificates with the same problem.
- Bdr representative — Explained that the affected certificate was issued via D-TRUST’s retail-customer application processing system, which was shut down for good on 19/07/2019, and stated that Managed PKI is now the only system for issuing TLS certificates.
- Bdr representative — Posted the final incident report, including a detailed explanation of how the issue was not detected in internal analysis due to a misunderstanding limited to the currently used Managed PKI platform, and listed remedial steps including revocation and technical/documentation changes.
- Mozilla representative — Asked whether there is a pre-issuance check ensuring future RSA key sizes are divisible by 8 and when adapted specification documents would be implemented.
- Bdr representative — Described existing pre-issuance checks (accepting only RSA key sizes 2048/3072/4096 and linting based on ZLint before CT logging) and clarified that documentation changes were already made.
- Mozilla representative — Stated the matter can be closed and intended to close it on Wed. 10-Mar-2021.