SwissSign: Certificate with key length 4098 bit
SwissSign reported that it was informed by a third party that it had issued a pre-certificate/certificate with a 4098-bit key length on 2019-08-05, which violates the Mozilla root store policy v.2.6.1 effective 2018-07-01. SwissSign stated that the SC31 “Browser alignment” became effective with BR 1.7.1 on 2020-08-20, and that the baseline regulation was not violated at that later time. SwissSign said it confirmed the misissuance after first and second analysis, and that only two certificates (a Pre and a Leaf) were affected. SwissSign stated it had stopped the issue from recurring by implementing and testing technical controls in January 2020, and it explained that invalid key lengths are denied in the request handler before linting or issuing the pre-certificate. The CA reported revocation of the certificate until 2021-02-13 (within 5 days since acknowledging the misissuance) and later stated the certificates were revoked as of 2021-02-12 13:25:32 UTC. Mozilla indicated it would schedule to close the case on 2021-03-10, and the bug is resolved as FIXED.
- SwissSign issued a pre-certificate/certificate with a 4098-bit key length.
- SwissSign received a third-party report about the 4098-bit key length misissuance.
- SwissSign acknowledged the report and confirmed the misissuance after analysis.
- SwissSign revoked the affected certificates.
- Mozilla scheduled closure of the case.
- SwissSign AG — SwissSign reported that it was informed by a third party of a 4098-bit key length misissuance on 2019-08-05, confirmed only two certificates were affected, and stated revocation actions and remediation controls.
- Mozilla representative — Mozilla asked whether SwissSign scans its database for existing certificates with the issue when adding controls, and if not, why not.
- SwissSign AG — SwissSign replied that it usually scans but had no explanation for why it did not do so after implementing the technical control.
- SwissSign AG — SwissSign stated the certificates were revoked as of 2021-02-12 13:25:32 UTC.
- Mozilla representative — Mozilla asked how the January 2020 technical control prevents future problems and what it covers.
- SwissSign AG — SwissSign explained that invalid key lengths are denied in the request handler before linting or issuing the pre-certificate, applying to all certificates of its public roots.
- Mozilla representative — Mozilla said it would schedule to close the case on 2021-03-10.