e-commerce monitoring GmbH: certificate issued with two pre-certificates
The case concerns an issuance incident for a leaf certificate where the CA’s internal control system showed that there were two pre-certificates associated with one leaf certificate. The CA stated this occurred because the first pre-cert issued did not have enough CT-log timestamp entries, leading to a follow-up pre-cert. The CA reported that its technical check systems (Cablint, x509lint, zlint) did not produce errors or warnings. The CA also stated that it was not possible for it to issue a leaf certificate with the same serial number, and that it revoked the unused pre-certificate identified during analysis. In response, the CA converted its software to a new CT log URL format and revised the relevant module, and it implemented programmatic measures to prevent pre-certificates with the same serial number from being issued. The CA later reported additional improvements, including more closely monitoring the list of usable CT log servers, and stated that it considered the underlying problem remediated with no further changes planned at the time. The bug was resolved as FIXED.
- The CA’s internal control system detected two pre-certificates for one leaf certificate and identified the cause as insufficient CT-log timestamp entries on the first pre-cert.
- The CA responded to a related report and described remediation steps, including programmatic measures to prevent duplicate pre-certificates by serial number.
- The CA reported further improvements and stated the underlying problem was remediated with no further changes planned.
- Mozilla planned to close the bug unless additional questions or concerns were raised.
- e-commerce monitoring GmbH — Opened the incident report describing issuance of one leaf certificate with two pre-certificates, the CT-log timestamp/URL-format cause, and remediation steps including revocation and software/module changes.
- Google representative — Asked for specific steps the CA took to detect future CT log operator changes in time and requested lessons learned from the incident.
- Zeger representative — Described an automated check of relevant CT log files (including log_list.json.auto.html) and stated a general lesson about not trusting external services not developed entirely by the CA.
- Mozilla representative — Asked whether the bug should be categorized as uncategorized or as an OV misissuance item.
- Mozilla representative — Requested a status update on the bug.
- e-commerce monitoring GmbH — Reported additional improvements (monitoring usable CT log servers and preventing same issuer/serial number situations) and stated no further changes were planned.
- Mozilla representative — Indicated the bug would be closed on 11-Oct-2023 unless additional questions or concerns were raised.