KIR: SZAFIR Trusted CA4 Intermediate CA certificate policies extension non-compliance (Reserved Certificate Policy Identifiers missing)
Krajowa Izba Rozliczeniowa S.A. (KIR) reported an incident where two intermediate certificates were incorrectly issued. In the SZAFIR Trusted CA4 Intermediate CA certificate, the Certificate Policies extension was missing Reserved Certificate Policy Identifiers that indicate adherence and compliance with TLS BR. KIR said it was first notified by an email message from Rob Stradling sent to k**********t@kir.pl. KIR stated that the issue was caused by an updated CA generation procedure that contained an incorrect value in the Certification Policy field, which the operator used during the CA generation ceremony on September 16, 2024. KIR updated its procedures to include all possible extensions and DN values, added a compliance-department check before generating a certificate, reviewed certificate profiles on its root CA system, and implemented an automatic linter for intermediate CA certificate checks. KIR also stated that the affected CA certificate (https://crt.sh/?caid=369967) was revoked on September 30, 2024, and that the CCADB record was updated. The bug was resolved as FIXED, and Mozilla requested a closure summary; KIR provided it and Mozilla indicated it intended to close the case on 19-Feb-2025 unless further discussion was needed.
- Two intermediate certificates were incorrectly issued during SZAFIR Trusted CA4 Intermediate CA certificate generation.
- KIR was first notified by an email message from Rob Stradling about the issue.
- The affected CA certificate was revoked and the CCADB record was updated.
- KIR reported that all action items were completed.
- Mozilla indicated it intended to close the bug on 19-Feb-2025.
- Kir representative — Opened the incident report describing two incorrectly issued intermediate certificates and missing Reserved Certificate Policy Identifiers in the Certificate Policies extension, including the stated root cause and action items.
- Kir representative — Reported that https://crt.sh/?caid=369967 has been revoked.
- Mozilla representative — Asked Mozilla to ensure the CA record is updated in the CCADB.
- Kir representative — Confirmed the CCADB record is updated.
- Kir representative — Reported that the action item to implement an automatic linter for intermediate CA certificate checks was completed.
- Kir representative — Stated that all action items have been completed and there were no further updates.
- Mozilla representative — Requested a Closure Summary and provided a template for describing incident, root cause, remediation, and completion of action items.
- Kir representative — Provided the Incident Report Closure Summary, including incident description, root cause, remediation, and commitment summary, and requested closure.
- Mozilla representative — Indicated intent to close the bug on Wed. 19-Feb-2025 unless further discussion was needed.