IdenTrust: TLS Certificates with outdated certificate profile
IdenTrust reported that it discovered seven active TLS subscriber certificates were issued using an outdated certificate profile that was no longer supported by the TLS Baseline Requirements (BR) as of 2024-09-15. The outdated profile issues included an incorrect inclusion of a userNotice in the Certificate Policies extension and Subject field attributes not arranged in the predefined relative order required by the BR. IdenTrust stated that it identified the root cause as a failure to update the certificate profile to align with the latest TLS BR that came into effect in September 2023. After discovery, IdenTrust completed revocation of the seven certificates on 2024-09-13 and later disclosed a preliminary incident report in Bugzilla on 2024-09-16. IdenTrust also revised its timeline and root cause analysis in response to Mozilla questions, and reported that it improved its standard operating procedures so that certificate profile requests require Delivery Team signoff before deployment in production. The bug was marked RESOLVED with resolution FIXED, and IdenTrust stated on 2024-10-25 that it considered the outstanding items addressed and the issue resolved.
- IdenTrust updated TLS certificate profiles to be compliant with BR v2.0.0.
- A customer reported an issue retrieving a TLS certificate due to linting behavior.
- IdenTrust identified seven active TLS subscriber certificates issued with an outdated certificate profile.
- IdenTrust completed revocation of the seven certificates.
- IdenTrust disclosed a preliminary incident report in Bugzilla and notified roots stores.
- IdenTrust stated it had addressed outstanding items and considered the issue resolved.
- IdenTrust Services, LLC — IdenTrust disclosed a preliminary incident report stating it had found seven active TLS subscriber certificates issued with an outdated certificate profile and that the certificates were revoked on 2024-09-13.
- IdenTrust Services, LLC — IdenTrust provided a complete incident report with root cause analysis, impact details, and action items including improved SOP requiring Delivery Team signoff for certificate profile updates.
- Google representative — Mozilla asked for timeline granularity updates and additional RCA detail, including questions about detection timing, the role of low usage, and how Delivery Team signoff would prevent recurrence.
- IdenTrust Services, LLC — IdenTrust revised the timeline and root cause analysis in response to Mozilla’s questions, including updated UTC timestamps and details about the investigation and SOP changes.
- Google representative — Mozilla asked further follow-up questions about issuance remaining active, why misissued certificates were discovered later, and Delivery Team roles and processes.
- IdenTrust Services, LLC — IdenTrust clarified that issuance remained active but linter functionality effectively prevented customers from issuing certificates, and described investigation steps and Delivery Team responsibilities.
- IdenTrust Services, LLC — IdenTrust stated it believed all outstanding items were addressed and considered the issue resolved.
- Mozilla representative — Mozilla indicated it would pull the case back up on 1-Nov-2024 and consider closing if there were no further questions or issues.