eMudhra emSign PKI Services: CA Certificates not published in DER Encoded Format
An external researcher advised eMudhra that one of the CA certificates published at a specified AIA location was PEM encoded instead of the required DER encoding, which does not comply with RFC 5280 Section 4.2.2.1. eMudhra investigated and determined that all CA certificates published to the repository at encoded AIA URIs from 2018-02-20 to 2024-03-14 were PEM encoded due to a manual error in its publication process. The impact was described as minimal because no customers reported issues with certificate usage during the investigation, though 56 PEM-encoded certificates were published instead of the required DER format. eMudhra identified the correct DER-encoded files for all 56 certificates, published them in a pre-live environment for testing, and then published the DER-encoded certificates to the production repository at the specified AIA locations. eMudhra also reported action items including reviewing all CA certificates in the repository for encoding format and implementing enhanced validation checks for DER publication. The bug was marked RESOLVED with resolution FIXED after the incident was addressed and the certificates were replaced with DER-encoded versions.
- emSign CA began publishing 56 root and CA certificates to the cacert AIA file repository using PEM encoding instead of DER encoding (per later investigation).
- The period of PEM-encoded publication to the encoded AIA URIs ended (per later investigation).
- eMudhra initiated an incident after receiving an email from an external researcher about a PEM-encoded CA certificate at an AIA location.
- eMudhra published DER-encoded versions of the 56 affected certificates to the production repository at the specified AIA locations.
- Emudhra representative — Filed an incident report stating that 56 CA/root certificates were published as PEM instead of DER due to a manual publication process error, and described the investigation and remediation steps.
- Emudhra representative — Reported that all incident-related items were addressed, requested the incident be marked resolved, and listed action items including replacing the 56 certificates and adding enhanced validation checks.
- Mozilla representative — Indicated intent to close the bug on Friday, 30-Aug-2024.