Microsec: Misissuance of one OV certificate with Key Usage KeyEncipherment
This case concerns Microsec misissuing one OV TLS certificate with an incorrect Key Usage setting (KeyEncipherment). Microsec stated it first became aware of the problem via an incident report email received on 2021-08-31 9:36 AM. Microsec investigated the cause, including a configuration problem that allowed an ECC end-entity key to be issued using an RSA certificate profile, and it reported that the manual post-issuance quality control check did not recognize the fault. Microsec contacted the site owner and planned revocation, and it revoked the incorrect certificate on 2021-08-31 10:12 UTC. Microsec also reported that it did not need to suspend certificate issuance because its quick investigation found current policy documents and certificate profiles were OK. In later status reports, Microsec described training for Registration Officers and additional controls (including profile configuration checks and automated CABLINT/ZLINT checks), and it stated no further action was planned. The bug was resolved as FIXED.
- Microsec revoked the incorrectly issued OV certificate after investigating an incorrect Key Usage setting.
- Microsec representative — Microsec reported the incident timeline, described the configuration/profile cause, and stated it revoked the incorrect certificate after contacting the site owner.
- Microsec representative — Microsec provided a status report including Registration Officer training and additional preventive controls, and stated no further action was planned.
- Microsec representative — Microsec reported a quarterly self-audit and stated it found no certificate misissuance in the sampled period.
- Mozilla representative — Mozilla stated it would close the bug the next day unless issues were raised.