SwissSign: S/MIME wrong key Usage
SwissSign reported a certificate misissuance involving S/MIME certificates. The issue was identified during an internal review while preparing to go live with sponsor-validated S/MIME profiles on its legacy CA system. SwissSign determined that it issued sponsor-validated S/MIME certificates with the key usage 'key agreement', which did not match its SwissSign S/MIME CPR. SwissSign stopped the misissuances within 30 minutes of detection and started its certificate mis-issuance process, informed the audit body, and began root cause analysis. In total, 106 certificates were mis-issued (102 valid and 4 revoked), with first issuance on 2023-08-28 19:07 and last issuance on 2023-08-30 23:31. SwissSign later confirmed that all affected certificates are revoked and described planned improvements, including better communication between product management, engineering, and QA teams and aligning automated tests with the update process. The bug was resolved as FIXED, and Mozilla indicated it intended to close the ticket if there were no open questions.
- SwissSign began issuing S/MIME certificates using a new sponsor-validated profile as preparation for S/MIME BR on 1 September 2023.
- SwissSign detected a mismatch between its S/MIME CPR and the certificate KeyUsage during an internal review and stopped certificate issuance.
- SwissSign posted the Bugzilla incident report and started root cause analysis.
- SwissSign confirmed that all affected certificates are revoked.
- SwissSign reported deep-dive findings and process/test improvements and asked to close the bug if no questions remained.
- SwissSign AG — Created the incident report describing the misissuance cause (key usage 'key agreement' not removed during legacy CA configuration), the timeline, and the aggregate count of mis-issued certificates.
- SwissSign AG — Confirmed that all affected certificates are revoked and stated deep dive and planned improvements were still under way.
- SwissSign AG — Reported investigation into automated testing to prevent recurrence and set the next update date.
- SwissSign AG — Stated improvements were introduced to requirement engineering communication and that automated tests would be aligned with the update process; asked to close if no open questions.
- Mozilla representative — Asked whether there were any questions and said Mozilla intended to close the bug on 22 Sept 2023 if none.