Telia CA: Invalid email contact address was used for few domains
Telia CA reported that its previous email-based domain validation software could validate domains incorrectly, using an email target address for multiple unvalidated domains in the same request. Telia discovered the issue in internal routines related to email validation and determined it affected a small set of domains during 03–06/2020, with some certificates still valid at the time of discovery. Telia stated it had stopped creating illegal certificates after a change in the domain reuse period on 1 Oct 2021. Telia began revocation of affected certificates and reported that 2 of 7 illegal certificates were revoked/expired, while the remaining 5 were in critical, heavily used systems where Telia requested additional time to avoid major disturbance. Mozilla noted that a delayed revocation requires filing an additional incident report, and Telia created Bug 1737808 for the delayed revocation of 5 EE certificates. Telia later reported that all violating certificates were revoked (with a corrected date of October 29, 2021), and Mozilla indicated it would close the bug on February 16, 2022 unless further issues were raised. The bug is marked RESOLVED with resolution FIXED.
- Telia’s previous email-based domain validation software produced incorrect domain validation for a small set of domains (as later identified by Telia).
- Telia’s previous order validation software was closed October 2020 (as referenced by Telia).
- Telia’s change in domain reuse period expired problematic domains from early 2020, stopping creation of illegal certificates.
- Telia disclosed the issue in Bugzilla and described the affected certificates and planned revocation process.
- Telia created a separate delayed revocation incident report (Bug 1737808) for 5 EE certificates.
- Telia reported that all violating certificates were revoked (correcting the date).
- Mozilla planned to close the bug unless questions or issues remained.
- Teliasonera representative — Telia described that invalid email domain validation occurred due to a bug in previous validation software, provided affected certificate/CT links, and stated it would revoke certificates still using illegally validated domains.
- Mm representative — A reviewer asked for clarification because two referenced certificates had only a single SAN, making the trigger unclear.
- Teliasonera representative — Telia clarified that the issue related to seven domains in three certificates and explained how pre-validated/reused validation led to inclusion of single-SAN certificates.
- Teliasonera representative — Telia reported alarm system implementation, system verification, renewal/closure of domains, and that 2/7 illegal certificates were revoked/expired while 5/7 were delayed due to critical usage.
- Mozilla representative — Mozilla stated that delayed revocation requires filing an additional incident report and referenced the whiteboard tags for the delayed-revocation leaf.
- Teliasonera representative — Telia stated it created Bug 1737808 for delayed revocation of 5 EE certificates related to this incident.
- Teliacompany representative — Telia reported that all violating certificates were revoked, then corrected the date to October 29, 2021.
- Mozilla representative — Mozilla said it would close the bug on February 16, 2022 unless there were questions or issues.