certSIGN: Incorrect data in stateOrProvinceName
This case reports that certSIGN operators identified an issuance problem affecting an OV SSL pre-certificate where the stateOrProvinceName value was incorrect. The issue was triggered when, after an internal request for an OV SSL certificate, the RA operators created a pre-certificate and the CA software update caused the automatic verification (linter warnings) to be skipped due to a technical issue, allowing the pre-certificate to be issued. certSIGN stated that the problem was discovered during a second verification post-issuance, after which the pre-certificate was revoked. certSIGN reported that the root cause was a bug in the CA software update and that it was fixed by rolling back to the previous configuration. The CA said it would treat all warnings as exceptions and keep the update in production until 31 May 2022 while testing additional test cases. certSIGN also stated it would continue monitoring production certificate issuance and later reported that the planned update was deployed in production. The bug was resolved as FIXED, and Mozilla indicated it would be closed on or about 3 June 2022.
- An OV SSL pre-certificate was issued with an incorrect stateOrProvinceName due to a CA software update issue affecting linter warnings.
- The affected pre-certificate was revoked after the error was detected in post-issuance verification.
- certSIGN deployed the planned update in the production environment.
- certSIGN — Reported that an OV SSL pre-certificate was issued after linter warnings were skipped due to a CA software update bug, and that the pre-certificate was revoked after the incorrect stateOrProvinceName was found.
- Community commenter — Asked for more detail on how the system allowed the invalid stateOrProvinceName and how the operator decided to override the warning.
- certSIGN — Explained that the stateOrProvinceName was filled wrong on the CSR request, that the update prevented warnings from reaching the operator, and that the operator assumed linting succeeded; described the linter-based validation process and the identified weakness.
- certSIGN — Stated that certSIGN would continue monitoring production certificate issuance and would post another status update on April 29, 2022.
- certSIGN — Stated that certSIGN would continue monitoring and would post another status update until May 31, 2022.
- certSIGN — Reported that the planned update had been deployed in the production environment.
- Mozilla representative — Indicated Mozilla would close the bug on or about Friday, 3 June 2022.