← eMudhra Technologies Limited cases
Bugzilla #1914466
Certificate Problem Report
eMudhra emSign PKI Services: CA Certificates not published in DER Encoded Format
RESOLVED
FIXED
eMudhra Technologies Limited
AI Summary
eMudhra Technologies Limited faced an incident where 56 CA certificates were published in PEM format instead of the required DER format, violating RFC 5280. This issue arose due to a manual error in their publication process, which lacked adequate validation controls. Although no customer issues were reported during the investigation, the potential for non-compliance and interoperability problems was acknowledged. The team swiftly resolved the issue by replacing the incorrect certificates with the correct DER-encoded versions and implementing enhanced validation checks for future publications.
Chronology
- First CA certificate published in PEM format.
- Last CA certificate published in PEM format.
- Incident raised regarding PEM-encoded certificate.
- 56 DER-encoded certificates published to production.
Participants
Naveen Kumar ML
B Wilson
External References
Similar Local Cases
eMudhra: Invalid CRL signatures
eMudhra emSign PKI Services : Key Blocking Mechanism Fails to Validate Historical Public Key Reuse.
eMudhra emSign PKI Services : OCSP Responder Time Inconsistency
eMudhra emSign PKI Services: Policy Document Inconsistency
eMudhra: Failure to respond to a Problem Report within 24 hours
eMudhra: Delayed Publication of Issuing CA Certificates In CCADB
eMudhra emSign PKI Services : Issue with revocation as part of automated reissuance
eMudhra: CRL occasionally unavailable and returns 404 error