Telia: S/MIME certificates issued in violation of S/MIME BR v1.0.1
Telia reported that it issued three S/MIME certificates in violation of S/MIME Baseline Requirements (S/MIME BR) v1.0.1. Telia said it became aware of the issue during its monthly compliance review on 2023-10-02 for S/MIME certificates issued in September 2023, and identified that the certificates were issued on 2023-09-01 by a technically constrained CA to Telefonaktiebolaget LM Ericsson AB personnel. Telia stated the certificates were missing a required Policy OID for “S/MIME BR Sponsor validated Legacy (2.23.140.1.5.3.1)” and were missing the required organizationIdentifier in the Subject (attribute 2.5.4.97), violating S/MIME BR v1.0.1 sections 7.1.6.1 and 7.1.4.2.2(d). Telia opened an incident report in Mozilla Bugzilla and performed an immediate review and a full compliance check, stating that no other problematic certificates were found. Telia notified affected certificate holders and reported that the problematic certificates were revoked, with revocation timestamps later corrected in a follow-up comment. Telia later reported that remedial actions were completed, including deploying daily linting with digicert/pkilint to verify S/MIME certificate compliance, and requested closure; Mozilla indicated it would close the incident on 2024-01-26. The bug is resolved as FIXED.
- Three S/MIME certificates were issued via API calls by a technically constrained CA.
- Telia performed a monthly compliance review and identified three non-compliant S/MIME certificates from September 2023.
- Telia opened an incident report in Mozilla Bugzilla and completed an immediate review and full compliance check.
- Telia reported revocation of the problematic certificates and later corrected revocation timestamps for two certificates.
- Telia reported deploying daily linting with digicert/pkilint for S/MIME certificate compliance verification.
- Telia requested closure after planned tasks were completed; Mozilla scheduled closure for 2024-01-26.
- Teliacompany representative — Opened the initial incident report, describing the non-compliance findings and stating affected certificates would be revoked by 2023-10-04 17:00 EET.
- Teliacompany representative — Updated that the problematic certificates had been revoked and listed revocation times (as initially reported).
- Teliacompany representative — Corrected revocation timestamps for two certificates due to a copy/paste error.
- Teliacompany representative — Provided the full incident report and continued monitoring of action items.
- Teliacompany representative — Reported that Tasks 2 and 3 were fully satisfied and deployed as planned.
- Teliacompany representative — Reported daily linting deployment with digicert/pkilint to verify S/MIME certificate compliance and stated remedial actions were completed.
- Teliacompany representative — Requested the incident be closed, stating there were no further questions and all planned actions were completed.
- Mozilla representative — Stated the bug would be closed the next day (2024-01-26).