D-Trust: EV TLS/QWAC certificates used http QCStatement PDS links (ETSI EN 319 412-5 non-compliance)
D-Trust disclosed an incident involving EV TLS certificates that are also Qualified Certificates for Website Authentication (QWAC). The certificates contained a QCStatement extension with an http link to the corresponding PKI Disclosure Statements (PDS), and D-Trust stated that ETSI EN 319 412-5 (QCS-4.3.4-03) only allows an https link for PDS. After D-Trust was made aware of the issue, it stopped production of this special EV certificate type and decided to revoke the affected certificates. D-Trust reported that 25 TLS certificates were affected and that they were revoked on 2025-01-03 18:30 UTC. D-Trust also adjusted dedicated certificate profiles and extended the use of PKI Lint to check ETSI requirements for the relevant certificate profiles. In the closure summary, D-Trust requested closure and stated that all action items disclosed in the incident report had been completed, and Mozilla indicated it would be queued to close on 19-Mar-2025. The bug is marked RESOLVED with resolution FIXED.
- D-Trust began investigating a reported potential ETSI EN 319 412-5 violation related to EV TLS/QWAC QCStatement PDS links.
- D-Trust halted production of the affected EV certificate type and decided to revoke the affected certificates within five days.
- D-Trust revoked all affected EV TLS/QWAC certificates (25 total) after adjusting certificate profiles.
- D-Trust reported that an additional measure was in place: PKI Lint checks for ETSI requirements for the relevant EV TLS/QWAC certificate profiles.
- D-Trust submitted an incident report closure summary describing remediation and completion of action items.
- Mozilla indicated the case would be queued to close.
- Bdr representative — Opened a preliminary incident report stating that D-Trust issued EV TLS/QWAC certificates with QCStatement http links to PDS, which D-Trust said did not comply with ETSI EN 319 412-5, and that production was stopped and affected certificates would be revoked.
- Bdr representative — Submitted a final incident report stating that production was stopped, certificate profiles were adjusted, 25 affected certificates were revoked on 2025-01-03 18:30 UTC, and production restarted after adopting the certificate profile.
- Bdr representative — Posted a weekly update that there was nothing new to report and that D-Trust was on track.
- Bdr representative — Posted a weekly update that there was nothing new to report and that D-Trust was on track.
- Bdr representative — Reported that PKI Lint had been used to check ETSI requirements for the EV TLS certificates that are also QWACs since 31-01-2025.
- Bdr representative — Asked whether the incident could be closed.
- Mozilla representative — Requested a Closure Summary.
- Mozilla representative — Provided guidance on what the Closure Summary should include and requested attestation that action items were completed.
- D-Trust — Submitted the incident report closure summary, stating the incident description, root cause(s), remediation (revocation, profile modifications, PKI Lint extension), and that all action items were completed and closure was requested.
- Mozilla representative — Stated it would be queued to close on Wed., 19-Mar-2025.