IdenTrust: Invalid special characters in S/MIME Certificates
IdenTrust disclosed an incident involving improper encoding of special characters in the Subject common name field of S/MIME certificates, which was not in line with RFC 5280 section 7.1. The issue was discovered by IdenTrust’s engineering team and affected one active and one revoked S/MIME certificate, resulting in the mis-issuance of two certificates. IdenTrust reported that it revoked the affected active certificate and also revoked the other certificate that was already revoked, and it generated a replacement certificate for the active one. IdenTrust stated it updated its configuration to stop similar mis-issuance and identified that PKILint was not properly configured for the affected customer account, which prevented linting from completing. In its final report, IdenTrust provided a timeline and root cause analysis, and listed action items including configuring PKILint to scan all S/MIME certificate accounts and implementing a process to include linting configuration during enterprise customer onboarding. IdenTrust later confirmed that it implemented the linting process for both existing and new enterprise customers and considered the issue resolved; Mozilla indicated it would close the bug on 6-Sept-2024.
- A customer certificate was generated that later was reported as not working with the customer’s system.
- The affected certificate was revoked and a new certificate was generated.
- The active certificate was revoked and replaced.
- IdenTrust confirmed implementation of the linting process for existing and new enterprise customers.
- IdenTrust Services, LLC — IdenTrust opened a preliminary incident report stating it was investigating invalid special characters in the subject of S/MIME certificates and had revoked the active certificate and updated configuration to stop mis-issuance.
- IdenTrust Services, LLC — IdenTrust posted a final report describing a configuration issue causing improper RFC 5280 encoding, confirming mis-issuance of two S/MIME certificates, providing a timeline and root cause analysis, and listing completed and planned action items.
- IdenTrust Services, LLC — IdenTrust confirmed it implemented the linting process for both existing and new enterprise customers and considered the issue resolved.
- Mozilla representative — Mozilla indicated it would take a look at closing the bug on Friday, 6-Sept-2024.