IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
IdenTrust reported that, during normal operations, it discovered on 06 September 2023 that 114 S/MIME certificates had been issued after 01 September 2023 in violation of certificate details in the CA/B Forum S/MIME Baseline Requirements version 1.0 that took effect that day. The certificates were issued in violation of the 112-bit entropy requirements (68 certificates) and Subject DN attribute requirements for sponsor-validated (27 certificates) and individual-validated profiles (19 certificates). IdenTrust stopped issuance on 06 September 2023 and completed sending revocation notices to affected certificate holders by 07 September 2023. IdenTrust deployed a hotfix on 11 September 2023 to fix the entropy size issue and updated certificate profiles to include the subject givenName and surname attributes, then revoked all affected certificates and enabled a new issuance process for mailbox-validated S/MIME certificates on 11 September 2023. The thread also includes updates that IdenTrust implemented an updated S/MIME linting tool, with successful implementation reported on 20 January 2024 and the issue considered resolved. Mozilla indicated it would close the bug on 26 January 2024, and the bug is marked RESOLVED with resolution FIXED.
- Improper S/MIME issuance began, before IdenTrust discovered the compliance problem.
- IdenTrust discovered that 114 S/MIME certificates had been issued in violation of S/MIME Baseline Requirements v1.0 and stopped issuance.
- IdenTrust completed sending revocation notices to affected certificate holders.
- IdenTrust deployed a hotfix, updated certificate profiles, revoked affected certificates, and enabled a new issuance process.
- IdenTrust implemented the updated S/MIME linting tool and confirmed its functionality.
- IdenTrust Services, LLC — IdenTrust disclosed the incident, including the number of affected S/MIME certificates, the specific S/MIME Baseline Requirements sections violated, and the remediation timeline (stopping issuance, revocations, hotfix/profile updates, and re-enabling issuance).
- IdenTrust Services, LLC — IdenTrust created an attachment listing the IdenTrust S/MIME misissued certificates.
- IdenTrust Services, LLC — IdenTrust stated it was on track to implement an updated S/MIME linting tool no later than January 2024 and would provide a next update by November 30, 2023.
- IdenTrust Services, LLC — IdenTrust reiterated it was on track to implement the updated S/MIME linting tool by January 31, 2024 and would post a status update by December 29, 2023.
- IdenTrust Services, LLC — IdenTrust provided another status update, again stating it would post the next update by January 31, 2024.
- IdenTrust Services, LLC — IdenTrust reported it successfully implemented the updated S/MIME linting tool on 1/20/2024, confirmed functionality, and considered the issue resolved with no outstanding tasks.
- Mozilla representative — Mozilla stated it would close the bug on Friday, 26-Jan-2024.