e-commerce monitoring GmbH: SCTs embedded in a precertificate and related revocation follow-up
This case began when a third party reported that e-commerce monitoring GmbH had produced a correctly formed precertificate, a second precertificate containing an SCT extension, and a final certificate whose embedded SCTs did not match the corresponding precertificate. The reporter said the SCT extension in the precertificate violated RFC 6962, and later comments argued that the resulting certificate set also implicated duplicate issuer-and-serial-number handling and revocation timing. The CA investigated, said it would look into the issue, and later stated that the three signed data structures were revoked on 2023-03-30. The CA also filed a separate incident report, Bug 1830536, for the duplicate precertificate issue. Over time, the CA posted updated incident reports and described process changes, including checks to prevent SCTs and precertificate poison from appearing together and improved monitoring of usable CT log servers. Mozilla participants asked for a more complete incident report and, later, indicated the bug could be closed once the updated report was provided.
- A precertificate with an SCT extension and a related certificate set were reported for e-commerce monitoring GmbH.
- The three signed data structures were revoked.
- The CA said it had filed Bug 1830536 for the duplicate precertificate issue and described process improvements.
- Mm representative — Reported that e-commerce monitoring GmbH had produced a precertificate containing an SCT extension and a certificate with invalid SCT signatures.
- e-commerce monitoring GmbH — Said the CA would look into the issue and get back soon.
- Sectigo — Argued that the latest precertificate was misissued and that revocation was necessary and overdue.
- Zeger representative — Stated that certificate number 10:45:67:49:88:c4:db:00:76:89:b9 was revoked.
- e-commerce monitoring GmbH — Filed Bug 1830536 and said the community wanted the distinct issues separated.
- e-commerce monitoring GmbH — Posted an updated incident report describing the issuance problem, impact, timeline, root cause, and remediation steps.
- Mozilla representative — Said he would close the incident on or about 2024-04-17 unless there were additional comments or questions.