Firmaprofesional: incorrect reserved CA/B Forum OIDs in SSL certificates
Firmaprofesional reported that, during preparation of evidence for its annual external audit, its internal audit team discovered a typo in the CA/B Forum reserved OIDs included in its SSL certificate profiles. The CA stated that it was including incorrect reserved OIDs for SSL-OV and SSL-EV certificates (using 2.13.* values instead of the intended 2.23.* values). Upon discovery on March 22, 2021, Firmaprofesional stopped issuance at 09:30, updated the certificate profiles in its CA software, researched affected certificates, and restored issuance at 12:00 while beginning reissuance and customer/stakeholder communications. The CA reported 587 affected certificates, with first/last affected issuance dates for the “Secure Web 2020” and “Secure Web 2021” CA hierarchies. Firmaprofesional also stated it informed clients of the need for revocation and would revoke all affected certificates within 5 days; it later reported that the remaining affected certificates were revoked on March 27, 2021. The bug was resolved as FIXED, and the CA reported that zlint verifications were added to production and that self-updating certlint/zlint tooling and improved quarterly internal audits were implemented to verify against the latest libraries.
- First affected SSL certificate was issued by “AC Firmaprofesional - Secure Web 2020” with the incorrect reserved CA/B Forum OIDs.
- Firmaprofesional discovered a typo in CA/B Forum reserved OIDs in its SSL certificate profiles and stopped affected certificate issuance.
- Firmaprofesional reported that the remaining affected certificates were revoked.
- Isigma representative — Reported that an internal audit discovered a typo in CA/B Forum reserved OIDs in Firmaprofesional SSL-OV and SSL-EV certificate profiles, provided affected CA names and OID differences, and described the stop/restart, profile update, research, and reissuance/communications steps.
- Isigma representative — Added an attachment listing affected SSL certificates for the OID typo issue.
- Isigma representative — Provided updated CPS/SSL CP/certificate profile URLs reflecting the corrected OID profile.
- Isigma representative — Stated that clients were informed to revoke affected certificates and that all affected certificates would be revoked within 5 days.
- Isigma representative — Reported that the remaining affected certificates had been revoked, with last revocation at 2021-03-27 07:02:10 UTC.
- Isigma representative — Reported that zlint verifications were added to the production environment.
- Autoridad de Certificacion Firmaprofesional — Reported completion of tasks including a self-updating certlint/zlint environment and improved quarterly internal audits to verify against the latest zlint/certlink libraries.
- Mozilla representative — Indicated the ticket could be closed and planned to call it for closure on 11-June-2021.