eMudhra: emSign CA invalid AIA extension value (84 misissued SSL certificates)
This case reports that eMudhra’s emSign CA misissued 84 SSL certificates with invalid Authority Information Access (AIA) extension values. The CA said it first became aware of the problem on 06-Apr-2022 after receiving an email reporting a certificate with an invalid AIA value, and it confirmed the certificates were misissued on 06-Apr-2022. eMudhra initiated system configuration inspection and changes to mitigate the issue, completed verification that new issuances were proper, and scanned to identify affected certificates. The CA notified subscribers on 07-Apr-2022, completed revocation of the affected certificates on 07-Apr-2022, and issued replacement certificates that were verified for successful mitigation. In the thread, Mozilla reviewers asked for clearer root cause analysis and the CA provided additional details, stating the cause involved human error due to AIA configuration field misconfiguration and lack of UI intuitiveness. eMudhra also described remediation steps including changes to the admin application UI (with an expected patch date of 30-Apr-2022) and stated that the software update was deployed successfully and remediation was completed. The bug was resolved as FIXED.
- The first of the affected SSL certificates was issued with invalid AIA values.
- eMudhra received a report of an invalid AIA value and began investigating and mitigating the misissuance.
- eMudhra notified subscribers, completed revocation of affected certificates, and issued verified replacement certificates.
- eMudhra expected a patch to update descriptive UI field names for AIA configuration.
- eMudhra reported the software update was deployed and remediation actions were completed.
- Emudhra representative — Filed the incident report stating 84 SSL certificates were wrongly issued with invalid AIA values, described investigation/mitigation steps, and reported revocation and replacement issuance.
- Community commenter — Asked for clearer, more concrete root cause analysis and a redo of the incident report answers with specific details and timeline.
- Emudhra representative — Said an update would be posted within the next few days (before 14-Apr-2022).
- Community commenter — Questioned why the certificate list did not use the recommended crt.sh URL form and asked whether eMudhra follows the dev-security-policy mailing list.
- Emudhra representative — Provided crt.sh URLs for the listed certificates as an update to the thread.
- Emudhra representative — Provided an updated root cause analysis and remediation plan, including UI intuitiveness issues and a change request to update descriptive field names, with an expected patch by 30-Apr-2022.
- Emudhra representative — Reported no new updates and said the software update was scheduled for next week, with a closure update afterward.
- Emudhra representative — Reported the software update was deployed successfully, confirmed remediation was completed, and requested the bug be marked Resolved.