certSIGN: Subscriber precertificate issued without Certificate Policies
The case concerns certSIGN S.A. (including the Intermediate CA certSIGN Enterprise CA Class 3 G2 1) issuing a subscriber pre-certificate that lacked the Certificate Policies section. The issue was triggered when certSIGN RA operators, following an internal request for an OV SSL certificate, created a pre-certificate; certSIGN reported that a recently applied CA software update caused the automatic verification of the certificate profile Policies field to be skipped during pre-issuance technical control. certSIGN stated that a second verification post-issuance revealed the error and that the pre-certificate was revoked within 24 hours of issuance. certSIGN also reported that the root cause was a bug in the CA update that was corrected and verified, and that only one certificate was issued with the problem (crt.sh ID 6442253524). In response, certSIGN updated the corrected configuration for the linting endpoint and planned and then deployed a further CA update with a catch-all condition. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it would close on or about 1 June 2022 unless additional tasks were needed.
- certSIGN issued an OV SSL subscriber pre-certificate with missing Certificate Policies due to a CA software update issue.
- The pre-certificate was revoked after post-issuance verification identified the missing Certificate Policies.
- certSIGN rolled back the CA update configuration to the previous configuration.
- certSIGN deployed the planned production update to address the issue and prevent recurrence.
- Lebihan representative — Reported noticing a certificate (crt.sh ID 6442253524) that did not include the Certificate Policies section.
- certSIGN — Provided an incident description, stating the pre-certificate was issued due to a CA software update bug that skipped Policies verification, and that it was revoked within 24 hours.
- certSIGN — Stated certSIGN would continue monitoring production certificate issuance and post another status update on April 29, 2022.
- certSIGN — Stated certSIGN would continue monitoring and post another status update until May 31, 2022.
- certSIGN — Reported that the planned update had been deployed in the production environment.
- Mozilla representative — Indicated Mozilla would close the bug on or about 1 June 2022 unless additional tasks were needed.