NAVER Cloud Trust Services: commonName not in SAN (internal audit misissuance)
NAVER Cloud Trust Services reported a misissuance discovered during its internal audit for the second quarter. The CA stated it became aware that an OV SSL certificate issued via its internal certificate issuance system (NDCM) had a commonName that was not included in the Subject Alternative Name (SAN). The CA said it immediately revoked the affected certificate on 2023-07-25 10:43 and suspended wildcard certificate issuance through NDCM. In its incident report, the CA attributed the issue to missing validation in the wildcard certificate issuance logic (CN of the CSR not being validated against the applicant-entered domain that later populates SAN), and noted that the x509 lint applied to the CA failed to catch the “commonName not in SAN” condition. The CA reported applying an NDCM hotfix to disallow mismatched CN/domain requests and completing additional pre-linting based on Zlint in the CA application (completed 2023-08-21 07:30). Mozilla asked whether remediation was complete, and the CA confirmed the root cause was addressed and measures to prevent recurrence were fully implemented; the bug was resolved as FIXED.
- NAVER Cloud Trust Services issued an OV SSL certificate where the commonName was not included in the SAN.
- NAVER Cloud Trust Services revoked the affected certificate and suspended wildcard certificate issuance through NDCM after discovering the issue in an internal audit.
- NAVER Cloud Trust Services completed adding pre-linting based on Zlint to its CA application.
- Navercorp representative — Reported that an internal audit found an OV SSL certificate with commonName not in SAN, and stated the certificate was revoked and investigations were started.
- Navercorp representative — Posted a full incident report with a timeline, root cause, and remediation steps including an NDCM hotfix and planned CA-side pre-linting.
- Navercorp representative — Confirmed Zlint-based pre-linting was completed in the CA application on 2023-08-21 07:30.
- Mozilla representative — Asked whether the issue was fully remediated and whether measures were in place to prevent recurrence.
- Navercorp representative — Confirmed the root cause was addressed and recurrence prevention measures were fully implemented.
- Mozilla representative — Indicated intent to close the bug on 2023-09-29 unless further questions arose.