← NAVER Cloud Trust Services cases
Bugzilla #1843268
Certificate Misissuance
NAVER Cloud Trust Services: OV certificate issued with OU field
RESOLVED
FIXED
NAVER Cloud Trust Services
AI Summary
NAVER Cloud Trust Services issued an OV SSL certificate containing an Organization Unit (OU) field on June 28, 2023. Upon discovering this misissuance during a security check on July 13, 2023, the affected certificate was revoked the same day. Investigations revealed that the validation logic in their internal system failed to check for the OU field in externally generated Certificate Signing Requests (CSRs). Remedial measures, including updates to the validation logic and additional pre-linting checks, have been implemented to prevent future occurrences.
Chronology
- Issuance of certificate with OU field
- Detection of the OU field in the certificate
- Revocation of the affected certificate
- Decision to stop issuing certificates with externally generated CSRs
- Completion of pre-linting measures
Participants
Han Yong, Park
Matt Miller
Ben Wilson
External References
Similar Local Cases
NAVER Cloud Trust Services: commonName not in SAN
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension
NAVER Cloud Trust Services: DV Certificate issued with improperly validated
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
Digicert: Failure to include CPS URI in 1 certificate
SwissSign: Certificate with key length 16258
SwissSign: Mis-Issuance of S/MIME certificates