SECOM incident report for CN/SAN case-mismatch certificates
SECOM reported an incident involving 24 TLS server-authentication certificates whose subject commonName did not match the SAN dNSName byte-for-byte, though the values were case-insensitively equal. SECOM said it first learned of the issue from a reporter email on 2024-05-10 and initially believed the certificates were not violating the Baseline Requirements or current root programs. After receiving a reply from the Chrome Root Program on 2024-05-15, SECOM acknowledged the issue as mis-issuance under Chrome’s criteria and began its incident process. SECOM completed revocation of 37 certificates on 2024-05-20 and later stated that it now interprets BR section 7.1.4.3 as requiring a case-sensitive character-for-character match between commonName and SAN dNSName. The thread also records SECOM’s explanation of its linting history, including first-party pre-linting, zlint implementation on 2024-03-20, and later updates to action items and internal reporting practices. Mozilla indicated on 2024-07-18 that, since there were no remaining action items or questions, the bug was scheduled for closure.
- SECOM was notified of 24 TLS certificates with CN/SAN case-mismatch issues.
- SECOM acknowledged the certificates as mis-issuance under Chrome Root Program criteria.
- SECOM completed revocation of 37 certificates.
- Mozilla stated the bug would be closed due to no remaining action items or questions.
- Ml representative — SECOM opened the incident report and described 24 affected TLS certificates, its initial interpretation of the requirements, and its investigation into the CN/SAN mismatch.
- Apple representative — Clint Wilson said the wording still appeared to require case matching and questioned SECOM’s interpretation.
- Ml representative — SECOM said it completed revocation of 37 certificates and explained its pre-linting history and interpretation of the Baseline Requirements.
- Ml representative — SECOM confirmed it currently interprets BR 7.1.4.3 as requiring a case-sensitive character-for-character match.
- Ml representative — SECOM updated action items with dates for the oldest valid certificate, bug review, zlint implementation, mis-issuance confirmation, revocation deadline, and root cause analysis.
- Ml representative — SECOM added an action item to share its future mis-issuance reporting policy with members.
- Mozilla representative — Ben Wilson said there were no action items or questions left and scheduled the bug for closure.