← e-commerce monitoring GmbH cases
Bugzilla #1815534
Certificate Problem Report
e-commerce monitoring GmbH: SCT in precertificate
RESOLVED
FIXED
e-commerce monitoring GmbH
AI Summary
The case involves e-commerce monitoring GmbH issuing multiple signed data structures with the same serial number, which included a pre-certificate poison extension and SCTs, violating RFC 6962. The incident was reported on February 7, 2023, and led to discussions about compliance with Mozilla's Root Store Policy. The CA acknowledged the issue and took steps to revoke the problematic certificates, which were eventually revoked on March 30, 2023. Improvements to their certificate issuance process were also implemented to prevent similar issues in the future.
Chronology
- Bug filed regarding SCT issues in precertificate.
- Certificates with the problematic serial number were revoked.
- Incident report finalized and case closed.
Participants
Andrew Ayer
Daniel Zens
Hans Zeger
Rob
Ben Wilson
Aaron Gable
External References
Similar Local Cases
e-commerce monitoring GmbH: CN domain not in SAN
e-commerce monitoring GmbH: Revoked test website not using revoked certificate
e-commerce monitoring GmbH: CRLs with mismatched issuer
D-Trust: TLS Precertificates Exceeding the Maximum Validity Period Allowed by the TLS Baseline Requirements
e-commerce monitoring gmbh: precertificate validity does not match leaf certificate
SwissSign: duplicate serial number
SECOM: FUJIFILM intermediate CA Certificate not listed in audit statement
Actalis: CRL distribution point with ldap scheme