NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
NAVER Cloud Trust Services reported that it issued three ECDSA certificates for test websites that incorrectly included keyEncipherment in the keyUsage extension. The CA stated this violated Mozilla Baseline Requirements (BR) section "7.1.2.7.11 Subscriber Certificate Key Usage". NAVER Cloud Trust Services said it discovered the issue and, within 30 minutes, promptly revoked all three affected certificates and suspended certificate issuance pending further investigation. In its incident report, the CA identified the root cause as a manual certificate profile creation process combined with missing pre-lint lint sources (RFC 5480 and RFC 8813) from the pre-lint scope, which allowed the incorrect certificates to pass pre-lint. The CA reported actions including adding the missing ECDSA lint source(s) to the pre-lint system, investigating additional cases that pass lint checks, and improving the certificate issuance system to reduce manual settings and enforce BR-compliant keyUsage values. The CA later stated that analysis and actions were completed, and Mozilla indicated it would close the bug on 28-Aug-2024. The bug is marked RESOLVED with resolution FIXED.
- NAVER Cloud Trust Services issued three ECDSA certificates with incorrect keyUsage for test websites and then revoked them within about 30 minutes after discovery.
- NAVER Cloud Trust Services published a full incident report and detailed root cause and action items.
- NAVER Cloud Trust Services stated analysis and actions were completed; Mozilla planned closure.
- Navercorp representative — Posted a preliminary incident report describing three ECDSA certificates with keyEncipherment in keyUsage, the BR violation, and that the certificates were revoked within 30 minutes after awareness.
- Navercorp representative — Provided an incident report with impact, timeline, root cause (manual profile creation and missing RFC 5480/RFC 8813 lint sources), and action items including adding lint sources and improving issuance controls.
- Navercorp representative — Updated action item statuses, including completion of adding ECDSA lint source to the pre-lint system and setting requirements for test-environment generation and external lint validation before production.
- Navercorp representative — Refreshed action item statuses, marking the listed mitigations and process changes as completed.
- Navercorp representative — On behalf of NAVER Cloud Trust Services, stated that analysis and actions were completed and there was no new information since a prior comment.
- Mozilla representative — Indicated Mozilla would look at closing the bug on 28-Aug-2024.