NAVER Cloud Trust Services: DV Certificate issued with improperly validated
NAVER Cloud Trust Services reported a misissuance of a Domain Validation (DV) certificate due to improper validation during testing of their new certificate issuance service, NCP Certificate Manager. The certificate was issued on November 24, 2023, after a QA team member inadvertently accessed an approval link in an email, leading to a bypass of standard validation procedures. Upon realizing the error, NAVER revoked the certificate immediately and initiated an investigation. They identified the root cause as excessive access rights granted to the QA team and have since implemented measures to prevent recurrence, including modifying the email approval process. The incident has been resolved with no further misissuance found.
- A DV certificate was improperly validated and issued.
- The certificate was revoked immediately upon discovery of the issue.
- NAVER implemented changes to the email approval process to enhance security.
- Navercorp representative — NAVER Cloud Trust Services inform that a DV certificate was improperly validated and issued.
- Navercorp representative — An incident report was posted detailing the misissuance and corrective actions.
- Navercorp representative — NAVER confirmed that all analysis and actions have been completed.