eMudhra: emSign CA Invalid OrganizationalUnitName (DV certificates misissued with OU)
eMudhra reported that two DV SSL certificates were wrongly issued with an OrganizationUnitName (OU) value of “Domain Control Validated,” even though the OU field should not have been part of these certificates. eMudhra said it became aware of the problem after receiving an email on 07-Dec-2021 18:11 (Indian Time) reporting a certificate with invalid OrganizationalUnitName. eMudhra confirmed the mis-issuance, initiated investigation and system configuration inspection, scanned for additional affected certificates, and found one more similar DV certificate. The affected certificates were revoked, and replacement certificates were issued without the OrganizationalUnitName. eMudhra stated it stopped issuing certificates with the problem and resolved it for future issuances, and it initiated an immediate system change request to add technical validation for DV certificates to not include OU fields, with a planned release by 31-Dec-2021. eMudhra later updated that the OU-removal validation change was deployed in the last week of Dec-2021 and that remediation was completed; the bug was requested to be marked Resolved, and the resolution is FIXED.
- eMudhra received a report of a DV certificate with invalid OrganizationalUnitName and began investigating the misissuance.
- eMudhra revoked the affected DV certificates and issued replacement certificates without OrganizationalUnitName.
- eMudhra deployed a system change to technically validate DV certificates to not include OU fields.
- eMudhra confirmed remediation identified in the bug was completed and requested the bug be marked resolved.
- Emudhra representative — Reported that two DV SSL certificates were misissued with an invalid OrganizationalUnitName value, provided a timeline, stated issuance was stopped for future issuances, and described remediation steps.
- Google representative — Asked for specifics on the requested system changes, timing, prevention expectations, and review of other configurations.
- Emudhra representative — Explained the system change as adding technical validation for DV certs to not include OU fields, expected release by 31-Dec-2021, and described profile/configuration reviews by audit officers.
- Mozilla representative — Requested an update on remediation efforts.
- Emudhra representative — Updated that the OU-removal validation change was deployed in the last week of Dec-2021 and that no OU issues were found in subsequently issued certificates.
- Emudhra representative — Confirmed all remediation identified in the bug were completed and requested the bug be marked Resolved.