← NAVER Cloud Trust Services cases
Bugzilla #1908128
Certificate Misissuance
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
RESOLVED
FIXED
NAVER Cloud Trust Services
AI Summary
NAVER Cloud Trust Services issued certificates with an incorrect OCSP URI in the Authority Information Access (AIA) field on July 16, 2024. The misissuance was due to a human error during the profile creation process, where the OCSP URI for CA certificates was mistakenly used instead of the URI for end-entity certificates. Upon discovering the issue, the affected certificate was revoked within 30 minutes, and issuance was suspended pending further investigation. The CA has since implemented measures to prevent similar occurrences in the future.
Chronology
- Certificate issued with incorrect OCSP URI
- Certificate revoked within 30 minutes of discovery
- Improvements to certificate issuance system completed
Participants
Hogeun Yoo
Clint Wilson
External References
Similar Local Cases
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
NAVER Cloud Trust Services: OV certificate issued with OU field
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension
NAVER Cloud Trust Services: DV Certificate issued with improperly validated
NAVER Cloud Trust Services: commonName not in SAN
Telia: TLS incorrect AIA caIssuer URI and incorrect CDP
Microsec: Misissuance of one OV certificate with Key Usage KeyEncipherment
Telia: invalid IP value in SAN DNS field