Amazon Trust Services: Misissuance of Subordinate Per CPS
This case concerns Amazon Trust Services (operating a subordinate certificate on behalf of DigiCert) issuing a subordinate certificate that Amazon Trust Services stated may violate its CPS certificate profile for subordinates, specifically the requirement that a subordinate’s notAfter must not be later than the notAfter date of the signing certificate. Amazon Trust Services reported that it received a report on 2021-11-25 and then investigated, determining on 2021-11-25 that the certificate was issued in violation of the CPS and that revocation was required per CPS 4.9.1.2. Amazon Trust Services stated it had stopped certificate issuance and that it corrected the dates associated with the previously generated key pair in 2015, but it did not follow up with DigiCert to destroy the specific certificate identified in the report and it failed to revoke that certificate. After further review, Amazon Trust Services completed an audit and identified three additional intermediate certificates from the same 2015 ceremony with the same issue, and it revoked the certificates on 2021-12-08. Mozilla asked whether there were any other action items, and Amazon Trust Services stated there were none and that the incident could be closed. The bug is marked RESOLVED with resolution FIXED.
- Amazon Trust Services added error checking into its CA system to prevent setting a certificate notAfter date beyond the issuer’s notAfter date.
- Amazon Trust Services corrected the dates associated with previously generated key pairs and deleted old certificates in its CA system for key pairs it controlled.
- Amazon Trust Services received a report and began investigating a subordinate certificate it said may violate its CPS profile.
- Amazon Trust Services revoked the identified certificates.
- DigiCert — Trevoli described the reported CPS violation for subordinate notAfter dates, provided a timeline of prior actions, stated issuance was stopped, and asserted revocation was required.
- DigiCert — Corey Bonnell noted similarity to another crt.sh ID and argued the issues should be treated identically.
- Community commenter — Ryan Sleevi asked for relevant CPS discussions and where the “community decided” statement came from.
- DigiCert — Corey replied with comments inline, including references to CPS versions and a blog post about auditor/root program review.
- DigiCert — Trevoli stated an audit found three additional intermediate certificates with the same issue and that they were revoked on 2021-12-08.
- DigiCert — Trevoli provided SHA256 hashes and pointed to CRLs containing the certificates.
- Mozilla representative — Ben Wilson asked whether there were any other action items or if the incident could be closed.
- DigiCert — Trevoli said there were no other action items and that the incident could be closed.