Microsec: Misissuance of an EV TLS certificate without CPSuri
Microsec reported that it misissued an EV TLS certificate because the certificate did not contain the CPSuri link, which Microsec stated is mandatory for EV TLS certificates. Microsec said it did not react in time to the initial email reporting a potentially misissued certificate, and it opened this bug to focus on the certificate misissuance (with other related issues handled in separate bugs). Microsec investigated and determined the issue started with a certificate profile change released on 2023-08-29, when it removed policyQualifiers information based on its interpretation of CABF EVG requirements. Microsec modified its EV TLS certificate profiles, issued a new EV TLS certificate containing CPSuri, and revoked the misissued certificate. Microsec later reported that a total of 45 EV TLS certificates were misissued, and that revocation of the misissued certificates was completed, with two PSD2 certificates revoked later in a related bug. In the thread, Microsec stated there were no open issues remaining regarding this incident report, and Mozilla indicated it would close the bug on or about 28-Aug-2024.
- Microsec released a new version of its certificate profiles that led to EV TLS certificates being issued without required CPSuri information.
- Microsec received an email reporting a potentially misissued certificate.
- Microsec received a second email reporting a potentially misissued certificate and began investigation.
- Microsec opened this Bugzilla incident report focusing on certificate misissuance.
- Microsec issued a corrected EV TLS certificate containing CPSuri and revoked the misissued certificate.
- Microsec reported revoking 44 of 46 misissued certificates.
- Microsec reported revoking the remaining 2 PSD2 misissued certificates and finishing revocation of all misissued certificates.
- Mozilla asked whether anything remained to be done; Microsec said no open issues remained and Mozilla planned to close the bug on or about 28-Aug-2024.
- Microsec representative — Opened the incident report, stating Microsec misissued an EV certificate missing CPSuri and describing the investigation and corrective actions, including issuing a new CPSuri-containing certificate and revoking the misissued one.
- Microsec representative — Provided an incident status update, including that 44 of 45 misissued certificates were issued/replaced and that revocation progress and customer coordination were underway, with PSD2-related items handled in Bug #2.
- Microsec representative — Reported that 44 of 46 misissued certificates were revoked and that 2 PSD2 certificates would be revoked later, referencing Bug #2.
- Microsec representative — Reported that the revocation of all misissued certificates was finished after the remaining 2 PSD2 certificates were revoked.
- Microsec representative — Shared additional details for checking revocation status, including serials and revocation information for affected certificates.
- Microsec representative — Described process improvements to prevent similar errors, explaining how certificate profile change management failed to account for different EV certificate requirements.
- Mozilla representative — Asked whether anything remained to be done regarding the incident report.
- Microsec representative — Stated there were no open issues regarding this incident report.
- Mozilla representative — Indicated the bug would be closed on or about Wed. 28-Aug-2024.