Firmaprofesional: 2022 - Title field length control finding from annual eIDAS/ETSI audit
This case is a self-disclosed finding by Autoridad de Certificacion Firmaprofesional identified during its annual eIDAS/ETSI audit. The finding concerned a certificate subject:title field being larger than the size allowed by RFC 5280 for one sample certificate under the QCP-n profile. The CA stated that this does not apply to TLS certificates and that, due to measures taken to resolve Bug 1717795, TLS certificate fields already have strict technical length controls. Firmaprofesional explained that character limitation controls were implemented for all fields of TLS certificates and most other certificate policies, but the limit was forgotten for the optional title field. In response, the CA updated its controls by uploading the technical control of the Title field to PRO, checking all fields for technical character limitations for policies QCP-n and QCP-l, and verifying enforcement of the character-limit controls. The CA indicated it considered the ticket ready to close, and Mozilla stated it would close it on or about 20-July-2022. The bug is marked RESOLVED with resolution FIXED.
- Firmaprofesional opened a CA Certificate Compliance bug describing an audit finding about subject:title field length exceeding RFC 5280 limits for a QCP-n sample certificate.
- Firmaprofesional confirmed completion of the remediation steps, including uploading the Title field technical control and verifying character-limit enforcement.
- Mozilla indicated it would close the bug on or about this date.
- Autoridad de Certificacion Firmaprofesional — Opened the bug with details of an annual eIDAS/ETSI audit finding that one QCP-n sample certificate had a subject:title field larger than allowed by RFC 5280, and described remediation intentions (title field limit was omitted for the optional title field).
- Autoridad de Certificacion Firmaprofesional — Discussed reviewing similar incidents from other CAs and described an approach using dropdowns to avoid human error in certain certificate fields (comment later noted as not for this bug).
- Autoridad de Certificacion Firmaprofesional — Updated and confirmed remediation: Title field technical control uploaded to PRO, character-limit checks performed for QCP-n and QCP-l fields, and enforcement verified for controls already done for TLS certificate fields; requested closure.
- Mozilla representative — Stated the bug would be closed on or about next Wednesday, 20-July-2022.