← NAVER Cloud Trust Services cases
Bugzilla #1785865
Certificate Misissuance
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension
RESOLVED
FIXED
NAVER Cloud Trust Services
AI Summary
NAVER Cloud Trust Services issued 21 DV certificates without the required Subject Alternative Name (SAN) extension for three test domains on August 18, 2022. The certificates were revoked within three hours of issuance upon detection of the error. The issue arose from a bug in their new internal certificate issuance system, which was promptly addressed by halting its use and implementing a Precertificate Linting procedure to prevent future occurrences. An internal audit later revealed a similar misissuance incident, but corrective measures were already in place to avoid recurrence.
Chronology
- Initial issuance of certificates without SAN extension fields
- Detection of the missing SAN extension
- Revocation of all affected certificates
- Completion of Precertificate Linting procedure testing
- Release of automated Precertificate Linting procedure
- Discovery of an additional similar misissuance during internal audit
Participants
Han Yong, Park
Matthias
B. Wilson
External References
Similar Local Cases
NAVER Cloud Trust Services: OV certificate issued with OU field
NAVER Cloud Trust Services: commonName not in SAN
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
NAVER Cloud Trust Services: DV Certificate issued with improperly validated
Entrust: Subscriber provides private key with CSR
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
SwissSign: S/MIME NCP non ASCII symbols in email and SAN field wrong coding
Telia: TLS certificates issued in violation of TLS BR v2.0.1