certSIGN: CPS specifies md5 and sha1WithRSAEncryption as allowed signature types
The bug concerns certSIGN’s CPS text stating that the “Signature Algorithm” field in Table 7.1 allows md5WithRSAEncryption and sha1WithRSAEncryption (in addition to sha256WithRSAEncryption). The issue was raised after certSIGN was informed by a Bugzilla ticket on 2021-06-29 11:21 PDT that the CPS specifies these algorithms as usable signature types. certSIGN stated that there were no certificates issued with MD5 or SHA-1, and that technical controls were in place such that issuance using md5 or sha1 is not permitted. certSIGN reviewed the issue, drafted and internally validated a response, and then planned CPS updates to remove md5 and sha1 from Table 7.1. certSIGN reported that the planned steps were completed and that CPS version 1.33 was published in the certSIGN repository. Mozilla later indicated it would close the bug as “fixed,” and the bug is resolved with resolution “FIXED.”
- A Bugzilla ticket informed certSIGN that its CPS Table 7.1 listed md5WithRSAEncryption and sha1WithRSAEncryption as allowed signature algorithms.
- certSIGN reviewed the issue and drafted and internally validated a response plan to update the CPS documentation.
- certSIGN obtained approvals to publish an updated CPS version removing md5 and sha1 from Table 7.1.
- certSIGN published CPS version 1.33 and reported the bug as fully resolved.
- Thisisntrocket representative — Reported that certSIGN ROOT CA CPS section 7.1.1 Table 7.1 lists md5WithRSAEncryption and sha1WithRSAEncryption as allowed signature algorithms, and argued md5 and sha1 should be removed or moved to legacy profiles.
- certSIGN — Described how certSIGN became aware (via the Bugzilla ticket), stated no md5/sha1 certificates were issued and issuance using md5/sha1 is not permitted, and outlined remediation steps to update and publish CPS.
- certSIGN — Confirmed the planned remediation steps were completed and that CPS version 1.33 was published in the certSIGN repository.
- certSIGN — Asked Mozilla to review the published CPS v1.33 and mark the bug as Resolved or Fixed.
- Mozilla representative — Stated the bug would be closed as "fixed" next Wednesday, 14-July-2021.