D-Trust: Issuance of 15 TLS certificates with incorrect subject attribute (RDN) order
D-Trust reported that after September 15, 2023 it issued 15 TLS certificates from the subordinate CA “D-TRUST CA 2-2 EV 2016” where the subject attribute (RDN) order did not match the TLS Baseline Requirements. D-Trust stated that, as part of Ballot SC62, it changed the RDN order for publicly trusted TLS subordinate CAs, but the change was not completed for “D-TRUST CA 2-2 EV 2016,” resulting in a deviation from the TLS BRs. After being made aware, D-Trust stopped production, corrected the configuration, tested in a reference system, and then restarted production. D-Trust informed affected customers and supported them to replace and revoke the affected certificates; D-Trust also revoked the 15 affected certificates. In the thread, D-Trust also discussed follow-up issues related to notification timing and opened a separate bug (1893610) for additional non-compliance discovered during root cause investigation. D-Trust later reported implementing additional measures, including selecting and installing a second linter (PKILint) and running pre-issuance linting with two linters, and asked whether the incident could be closed; Mozilla indicated an intent to close it on or about 7-Aug-2024 unless further items were needed. The bug is marked RESOLVED with resolution FIXED.
- Ballot SC62 provisions entered into force for TLS subject attribute (RDN) order requirements.
- D-Trust began investigating and stopped production for the affected subordinate CA after identifying the RDN order deviation.
- D-Trust revoked all affected TLS certificates.
- D-Trust installed PKILint in its production system and began running two linters for pre-issuance linting.
- D-Trust reported that all measures were implemented and asked to close the incident.
- D-Trust — Filed a preliminary incident report describing the RDN order deviation, stopping production, correcting configuration, informing customers, and revoking 15 affected TLS certificates.
- D-Trust — Reported discovering an additional non-conformity (TLS BR 4.9.5) and opened follow-up incident report bug 1893610, linking to it.
- Community commenter — Asked when the full incident report would be posted.
- D-Trust — Responded to questions about the incident timeline and linting approach, stating tests were required before tools could be put into operation and describing use of ZLint plus additional measures outside ZLint.
- D-Trust — Explained that a final incident report was delayed due to discovery of further non-compliance, opened bug 1893610, and described expanded internal process guidelines and training.
- D-Trust — Clarified that no new lints were implemented in ZLint and that internal checks (organizational measures and CA system checks) were established by 2024-05-02.
- Bdr representative — Updated that D-Trust decided to implement PKILint as a second linter and was reviewing internal timelines.
- D-Trust — Reported successful installation and testing of PKILint in reference and production systems and that two linters are now used for pre-issuance linting.
- D-Trust — Reported that all measures were implemented and asked whether the incident could be closed.
- Mozilla representative — Stated an intent to close the bug on or about 7-Aug-2024 unless additional items needed discussion or explanation.