← certSIGN cases
Bugzilla #1718675
Policy Compliance
certSIGN: CPS specifies md5 and sha1WithRSAEncryption as useable signature types
RESOLVED
FIXED
certSIGN
AI Summary
The certSIGN Certification Practice Statement (CPS) originally included md5 and sha1WithRSAEncryption as acceptable signature algorithms. This raised concerns due to the known weaknesses of these algorithms. Following a report, certSIGN confirmed that no certificates had been issued using these algorithms and took immediate steps to update the CPS. The problematic algorithms were removed in the updated CPS version 1.33, which was published on July 8, 2021.
Chronology
- Issue reported regarding the inclusion of md5 and sha1 in CPS
- certSIGN conducted analysis and drafted a response
- Approvals obtained for the updated CPS
- Updated CPS version 1.33 published
Participants
Matthias
Gabriel PETCU
bwilson@mozilla.com
External References
Similar Local Cases
Google Trust Services: Signing SHA-1 Hash for existing CA certificate with changes in Key Usage
PKIoverheid / QuoVadis: CPS inconsistencies
Microsoft PKI Services: Failure to modify policy documents within 365 days
certSIGN: Non-BR-Compliant Certificate Issuance
D-Trust: Non-compliance of issued root and intermediate S/MIME certificates
Firmaprofesional: 2020 Audit Report Finding 1 out of 4
IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement
TWCA: Missing or Inconsistent Disclosure of S/MIME BR Audits