DigiCert: Issuance of certs with weak keys (ROCA)
This case concerns DigiCert certificates that were issued with keys impacted by ROCA (Return of the Coopersmith Attack). The issue was initially reported to DigiCert by Hanno Bock, who reported six ROCA-impacted certificates on December 2, 2021 and an additional three on December 3, 2021; DigiCert then confirmed the problems and expanded its investigation. DigiCert revoked the six reported certificates on December 3, 2021 and started revocation for the additional three, and it launched an internal scanner to detect whether any other certificates were impacted. DigiCert discovered one additional ROCA-impacted certificate and revoked additional certificates on December 4, 2021; the scan completed on December 7, 2021 with no further ROCA-impacted certificates detected. DigiCert stated it did not have a pre-issuance check for ROCA-affected keys at the time, and it explained that the ROCA check had been part of a legacy Symantec “Sentinel” system that was shut down in 2019, leaving a gap between DigiCert’s linting system and Sentinel. DigiCert later deployed a CA-level hard-block check for ROCA and close primes (and later extended it to its sMIME system), and the bug was marked RESOLVED with resolution FIXED.
- First ROCA-impacted certificate was issued.
- Last ROCA-impacted certificate was issued.
- DigiCert received a report of six ROCA-impacted certificates and began investigation.
- DigiCert revoked the six reported certificates and began revocation for additional reported certificates while launching an internal scanner.
- DigiCert discovered one additional ROCA-impacted certificate and revoked additional certificates.
- DigiCert’s scan completed and no additional ROCA-impacted certificates were detected.
- DigiCert deployed a CA-level ROCA/close-primes detection check as a hard block.
- DigiCert deployed the same checks to its sMIME system and indicated the bug was remediated.
- DigiCert — Jeremy Rowley described the ROCA incident, DigiCert’s investigation steps, revocations, and remediation actions, and provided CT links for the affected certificates.
- Sectigo — Rob asked for clarification reconciling a prior statement about stopping ROCA keys with the claim that DigiCert did not have a pre-issuance check for ROCA-affected keys.
- DigiCert — Jeremy explained that ROCA checking had been implemented in a legacy Symantec “Sentinel” system and that it was shut down in 2019, leaving ROCA checks absent from DigiCert’s own linting system.
- DigiCert — Jeremy clarified that the heartbleed check was added to a separate server inspector service rather than the linting tool.
- DigiCert — Jeremy stated DigiCert deployed a CA-level check to evaluate ROCA or close primes and that it hard-blocks detected keys.
- DigiCert — Jeremy reported deployment of ROCA, small prime, and close prime detection and blocks on all but the sMIME system.
- DigiCert — Jeremy reported the checks were deployed to the sMIME system and said the bug is remediated and ready to close unless further questions.
- Mozilla representative — B. Wilson said they would schedule the bug to be closed on or about Friday, 14-Jan-2022, unless further discussion was needed.