← NAVER Cloud Trust Services cases
Bugzilla #1908130
Certificate Misissuance
NAVER Cloud Trust Services: Incorrect keyUsage for ECC certificate
RESOLVED
FIXED
NAVER Cloud Trust Services
AI Summary
NAVER Cloud Trust Services issued three ECDSA certificates with an incorrect keyUsage of keyEncipherment, violating the Baseline Requirements. Upon discovery, the certificates were revoked within 30 minutes. The root cause was identified as missing lint sources in the pre-linting process, which allowed the mis-issuance to occur. The CA has since suspended certificate issuance and implemented corrective actions to prevent future occurrences.
Chronology
- Three ECDSA certificates issued with incorrect keyUsage.
- Certificates revoked within 30 minutes of discovery.
- Lint sources added to prevent future mis-issuance.
- Improvements to certificate issuance system completed.
Participants
Hogeun Yoo
Sooyoung Eo
B. Wilson
External References
Similar Local Cases
NAVER Cloud Trust Services: Certificate issued with incorrect OCSP URI in AIA
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension
Microsec: Certificate validity period greater than 398 days
ACCV: Certificates issued with cRLIssuer in CDP extension
NAVER Cloud Trust Services: OV certificate issued with OU field
NAVER Cloud Trust Services: commonName not in SAN
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
NAVER Cloud Trust Services: DV Certificate issued with improperly validated