IdenTrust: TLS ICA issued with disallowed “User Notice” policy qualifier; revoked and linter updated
IdenTrust reported that an intermediate CA certificate (ICA) was issued with the “User Notice” policy qualifier within the certificatePolicies extension, which it stated is no longer permitted by the CA/Browser Forum Server Baseline Requirements as of September 15, 2023. IdenTrust said the issuance was not BR compliant and that it came to their attention on May 9, 2024, via comment #12 on another IdenTrust Bugzilla bug (1895006). IdenTrust stated that the ICA was promptly revoked and that it established a process to ensure the Linter tool is updated with the most current validations. In its root cause analysis, IdenTrust said the Linter tool used to validate certificate issuance failed to detect the discrepancy because the version in use had not been internally updated with the latest validation checks. IdenTrust also discussed delaying the linter update from June 30, 2024, until July 20, 2024, and then stated that it successfully deployed the updated linter on July 20, 2024 and improved ongoing processes for keeping the linter tool up to date. The thread indicates no further remediation actions were pending as of August 20, 2024, and Mozilla indicated it would close the bug on August 23, 2024; the bug is resolved as FIXED.
- PKI operator created the ICA in a pre-production environment and it passed Linter validation for production issuance.
- PKI operations began key ceremony to create the ICA in production, including creation of a malformed self-signed Root CA and then the expected ICA.
- The new ICA was uploaded into CCADB.
- IdenTrust became aware of the issue and started the process to revoke the ICA.
- IdenTrust revoked the ICA.
- IdenTrust deployed the updated Linter during the scheduled change control.
- IdenTrust stated there were no further remediation actions pending.
- IdenTrust Services, LLC — IdenTrust opened the incident report stating an ICA was issued with a disallowed “User Notice” policy qualifier, that it was promptly revoked, and that the Linter tool needed updating; it also provided a timeline and action item to update the Linter tool.
- Community commenter — A commenter asked for missing details about when IdenTrust became aware of the BR change and what actions were taken after the ballot passed, and why the ICA profile was not updated.
- IdenTrust Services, LLC — IdenTrust responded that it was aware of proposed profile updates since February 2023 and that ballot SC-62v2 was adopted effective September 15, 2023; it described its BR compliance process and stated the ICA profile update failed due to human oversight and a failed technical control (missing updated linter).
- IdenTrust Services, LLC — IdenTrust stated it would delay updating the linter tool from June 30, 2024 to July 20, 2024 and explained its rationale.
- IdenTrust Services, LLC — IdenTrust reported that it successfully deployed the updated linter on July 20, 2024.
- IdenTrust Services, LLC — IdenTrust reported that it improved and implemented ongoing processes for keeping the linter tool up to date.
- IdenTrust Services, LLC — IdenTrust stated there were no further remediation actions pending for the issue.
- Mozilla representative — Mozilla indicated it would look at closing the bug on Friday, 23-Aug-2024.