NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
NAVER Cloud Trust Services reported that, on 2024-07-16, its NAVER Cloud Trust Services G1 ECC CA1 intermediate CA issued certificates for test websites with an incorrect OCSP URI in the Authority Information Access (AIA) extension. The issue was detected via sslmate OCSP WATCH, which reported an error parsing the OCSP response due to an ECDSA verification failure. NAVER Cloud Trust Services stated that it revoked the affected certificate within 30 minutes of becoming aware of the problem and suspended certificate issuance while investigating. In its incident report, the CA attributed the root cause to human error when creating a certificate profile: the OCSP URI intended for CA certificates was entered instead of the OCSP URI intended for end-entity certificates. The CA also described action items to prevent recurrence, including changing the certificate issuance system so AIA extension caIssuer and OCSP URI values are selected from constants rather than manually entered, and adding verification logic to cross-check that the OCSP URI and caIssuer URI match the intended CA purpose. The bug was marked RESOLVED with resolution FIXED, and the CA later stated that analysis and actions were completed with no new information since the prior comment.
- NAVER Cloud Trust Services issued test-site certificates with an incorrect OCSP URI in the AIA extension, then revoked the affected certificate within about 30 minutes and suspended issuance.
- Navercorp representative — Posted a preliminary incident report stating the incorrect OCSP URI was detected by sslmate OCSP WATCH and that the affected certificate was revoked within 30 minutes; also said issuance was being suspended and a full report would follow by 2024-07-23.
- Navercorp representative — Provided an incident report describing the mis-issuance, impact, timeline, root cause (human error entering the wrong OCSP URI in the AIA field during certificate profile creation), and action items to prevent manual misconfiguration and add verification logic.
- Apple representative — Requested additional detail about the necessity of manual certificate issuance/profile creation, the controls around profile configuration and issuance, and how these systems relate to another incident (1908130) and to NAVER Global Root CA operations.
- Navercorp representative — Responded with details of the certificate profile creation process, including development-environment testing and production profile creation steps, and discussed prior technical controls such as pre-lint validation.
- Navercorp representative — Updated the action items status, stating implementation was in progress for constant selections for AIA caIssuer/OCSP URI and for adding cross-verification logic.
- Navercorp representative — Updated the action items status to completed for both the constant-selection change and the added verification logic.
- Navercorp representative — Stated that analysis and actions were completed and that there was no new information since the prior comment.
- Mozilla representative — Indicated they would look at closing the bug next Wednesday (28-Aug-2024).