KIR S.A. reported certificates with CN not present in SAN and later deployed a software fix
This case concerns KIR S.A. reporting a certificate issuance problem where the certificate CN domain was not present in the SAN. The issue was first raised by an external reporter who linked to affected crt.sh entries and asked how the domains had been validated. KIR said it investigated, prepared incident response, and identified that DNS TXT validation had been used for the domain pocztowy.pl. KIR later stated that it found two affected certificates, revoked one certificate, and said the other was already revoked and would be replaced. The CA explained that the root cause was missing technical validation between CN and SAN fields in its software and procedures, and it worked with its vendor while also adding procedural controls and operator awareness steps. KIR later said it built and tested a patch, deployed the solution to production on 2021-08-30, and then asked to close the bug.
- A certificate was issued with a CN domain not present in SAN.
- One affected certificate was revoked.
- KIR said it had found a second certificate with the same issue.
- KIR deployed the solution to production.
- Lebihan representative — Reported a precertificate with CN domain not in SAN, noted it was revoked, and asked for the related incident report.
- Kir representative — Said KIR was investigating the issue and preparing incident response, and stated that pocztowy.pl had been validated.
- Kir representative — Confirmed that DNS TXT validation was used.
- Kir representative — Said KIR found another certificate with the same issue and stated there were two affected certificates.
- Kir representative — Provided a timeline, said one certificate was revoked and the other would be replaced, and described procedural updates and a vendor ticket.
- Kir representative — Said the basic patch functionality was delivered and estimated production deployment by the end of August.
- Kir representative — Explained that KIR decided to build the patch itself after vendor discussions and identified Verizon UniCERT as the software vendor.
- Kir representative — Stated that the solution was deployed to production.
- Kir representative — Asked whether the bug could be closed.
- Mozilla representative — Said the bug would be closed on 2021-09-10 if there were no further comments.