E-Tugra incident report on internet-accessible internal application and potential certificate-management impact
E-Tugra opened this bug to disclose a security incident involving an internal application that was mistakenly made internet-accessible. The company said it first learned of the issue from an email by Ian Carroll on 2022-11-13, fixed the affected sites immediately, and began scanning and reviewing systems and access controls. In the thread, E-Tugra stated that the affected application was for reporting and that its CA systems were physically and logically separated, while participants repeatedly asked whether the exposed system could have affected certificate issuance or customer account access. E-Tugra later said the application did not participate in certificate issuance, that SSL.com handled domain validation for managed SubCAs during the transition period, and that no evidence showed malicious exploitation of the vulnerability. The case remained focused on incident response, penetration testing, remediation, and clarifying the relationship between the exposed application, customer portal functions, and the publicly trusted CA hierarchies. The bug was ultimately resolved as FIXED after E-Tugra posted an updated incident report and a penetration testing executive summary.
- E-Tugra learned of the internet-accessible internal application from Ian Carroll and fixed the affected sites the same day.
- E-Tugra published an incident report describing the security issue and response.
- E-Tugra said the expanded penetration testing exercise was completed.
- E-Tugra posted an updated incident report.
- E-Tugra posted an executive summary of the penetration testing and verification report.
- E-Tugra — E-Tugra filed the incident report, said it learned of the issue from Ian Carroll, and described immediate fixes and follow-up scanning.
- Google representative — Chris Clements asked for a more detailed timeline, separation details, and evidence about the scope and impact of the incident.
- E-Tugra — E-Tugra said its CA and non-CA systems were physically and logically separated and that the incident involved an internal non-SSL application.
- E-Tugra — E-Tugra said it ran monthly vulnerability scans, annual penetration tests, and a February 2022 risk assessment, and that upcoming testing would cover CA and non-CA systems.
- E-Tugra — E-Tugra said the reporting system received CA log information through secure tunneling and that the application did not directly participate in certificate issuance.
- E-Tugra — E-Tugra said the customer portal allowed re-issuing already validated DV certificates, but the accessed application did not affect that process.
- E-Tugra — E-Tugra said it found no evidence of malicious exploitation and had checked logs and issued certificates for impact.
- E-Tugra — E-Tugra said remediation measures were in place and that penetration testing was the only remaining action item.
- E-Tugra — E-Tugra said SSL.com managed SubCAs during the transition period and that the exposed application only stored logs for reporting purposes.
- E-Tugra — E-Tugra confirmed multiple SSL.com-managed SubCAs, said SSL.com handled domain validation, and said it would present evidence to LSTI auditors.
- E-Tugra — E-Tugra attached an updated incident report and said the detailed penetration testing reports would follow.
- E-Tugra — E-Tugra attached an executive summary of the penetration testing and listed several low-level findings.