KIR: SZAFIR Trusted CA3 intermediate CA certificate policies extension non-compliance (Reserved Certificate Policy Identifiers missing)
Krajowa Izba Rozliczeniowa S.A. (KIR) reported that an incident occurred where one intermediate certificate was incorrectly issued. Specifically, the Certificate Policies extension in the SZAFIR Trusted CA3 Intermediate CA was missing Reserved Certificate Policy Identifiers indicating adherence and compliance with the S/MIME BR. KIR said it was first notified by an email message from Rob Stradling posted to k**********t@kir.pl. KIR stated the impacted intermediate CA certificate had not yet been revoked at the time of the report and that it was developing a plan to safely switch issuance to a new intermediate CA certificate and retire or revoke the SZAFIR Trusted CA3 intermediate CA certificate, with a migration plan to be posted until Oct 11, 2025. In the thread, KIR described the root cause as an incorrect value in the Certiifcation Policy field in an updated CA generation procedure used during the Oct 11, 2023 generation ceremony. KIR reported remediation including updating CA generation procedures, adding a compliance check, reviewing certificate profiles, and implementing an automatic linter for intermediate CA certificate checks; KIR also stated the migration plan and revocation date of the impacted certificate had been executed. Mozilla requested a closure summary, and KIR provided one and requested closure; Mozilla indicated it would close the bug on 19-February-2025 unless remaining issues were discussed. The bug is marked RESOLVED with resolution FIXED.
- SZAFIR Trusted CA3 intermediate CA certificate was generated using an updated procedure containing an incorrect Certiifcation Policy field value.
- KIR was notified by email from Rob Stradling about the intermediate CA certificate issue.
- Intermediate CA certificate profile was updated to be compliant with S/MIME BR.
- Automatic linter for intermediate CA certificate checks was reported as completed.
- KIR submitted an incident report closure summary and requested closure.
- Mozilla closed the incident unless remaining issues were discussed.
- Kir representative — Opened the incident report describing the incorrectly issued intermediate certificate and the missing Reserved Certificate Policy Identifiers in the Certificate Policies extension.
- Sectigo — Quoted S/MIME BR section 4.9.1.2 and warned that failing to revoke the Szafir Trusted CA3 intermediate certificate within seven days would cause another incident.
- Kir representative — Responded that KIR was aware of the seven-day revocation requirement but would file a new incident for delayed revocation at the right time due to the impact described.
- Kir representative — Reported that the action item to implement an automatic linter for intermediate CA certificate checks was completed.
- Kir representative — Stated that all action items had been completed and there were no further updates.
- Mozilla representative — Requested a Closure Summary template and asked KIR to attest that all action items were completed.
- Kir representative — Provided the closure summary, including incident description, root cause, remediation, and commitment summary, and requested closure.
- Mozilla representative — Indicated Mozilla would close the bug on 19-February-2025 unless remaining issues were discussed.