DigiCert: SMIME certificate issued with unvalidated information (missing SMIME BR OID)
DigiCert reported that, on 20 February, its internal checks identified a single S/MIME certificate that had been issued with unvalidated information and was missing the SMIME BR OID. DigiCert stated that the certificate was revoked. The investigation attributed the issue to a disaster recovery (DR) system that activated during system patching; this DR system was running older code that predated the S/MIME BRs. DigiCert said the DR system issued only one certificate before operations resumed at the production site, and that firewall rules prevented external certificate requests from the DR endpoint. DigiCert reported remediation steps including version monitoring for production and DR instances and uptime checks on DR instances, and it stated that it fixed the issue on 20 February and added it to an automated DR sync. Mozilla participants asked for clarification on the DR update procedures and firewall behavior; DigiCert responded that the impacted DR system was the one mentioned in the bug, that DR code and production code are deployed at the same time with a deployment success test, and that databases are continuously synced. The bug was marked FIXED, and DigiCert indicated it was monitoring for further questions before Mozilla closed it on 29 March 2024.
- A certificate was issued by the disaster recovery system during a period when older DR code was in use.
- DigiCert’s internal checks identified the non-compliant S/MIME certificate and DigiCert revoked it.
- DigiCert fixed the DR issue and added it to an automated DR sync.
- Version monitoring for production and DR instances was completed.
- Uptime checks on DR instances were completed.
- Mozilla closed the bug after no further questions were raised.
- Community commenter — Martin Sullivan reported that DigiCert was made aware via internal checks of a single SMIME certificate issued with non-validated information and said it had been revoked while the investigation continued.
- Community commenter — Martin Sullivan provided a reproduction/timeline and root cause analysis describing DR activation with older code, and listed action items (version monitoring and DR uptime checks).
- Community commenter — Martin Sullivan asked whether Mozilla was okay to close the bug given remediation completion.
- HARICA — Dimitris Zacharopoulos requested additional incident-report details, including when the DR code was updated and questions about DR instance impact and sync/testing processes.
- DigiCert — Jeremy Rowley answered that the issue was fixed on Feb 20 and added to automated DR sync, clarified only one DR system was impacted, and described deployment/sync testing and firewall behavior.
- HARICA — Dimitris Zacharopoulos acknowledged the clarifications and stated he had no further questions.
- Community commenter — Martin Sullivan stated DigiCert was monitoring for any further questions.
- Community commenter — Martin Sullivan asked if the bug could be closed.
- Mozilla representative — Ben Wilson said he would close the bug on Friday, 29-Mar-2024, unless additional questions were raised.