Sectigo: Issuance of ECC leaf certificates with non-DER encoded keyUsage
Sectigo discovered that some ECC leaf certificates issued by its CA platform contained an incorrect number of unused bits in their keyUsage BITSTRINGs. This issue was identified on October 20, 2022, through a linting tool. To mitigate further misissuance, Sectigo upgraded its preissuance linting system and deployed a bugfix the same day. They also initiated a script to identify all affected certificates, which ultimately identified 322,161 unique serial numbers. Sectigo decided not to revoke the affected certificates within the usual timeframe and opened a separate bug to explain this decision. The case has since been resolved.
- Sectigo discovered the issue with ECC leaf certificates.
- Sectigo deployed a bugfix to prevent further misissuance.
- Sectigo decided not to revoke the affected certificates.
- Sectigo — We discovered that some ECC leaf certificates contain an incorrect number of unused bits in their keyUsage BITSTRINGs.
- Mozilla representative — Thanks, Rob, for your rapid response. This is very noteworthy.
- Sectigo — We propose that this bug should now be closed.
- Mozilla representative — I will close this on or about Monday, 28-Nov-2022, unless there are additional questions.