HARICA: S/MIME mailbox-validated certificates issued without proper email validation
HARICA reported an incident after receiving a certificate problem report from a subscriber about HARICA S/MIME certificate issuance. The subscriber stated that a flaw in the S/MIME workflow permitted issuance of mailbox-validated certificates without proper validation of the email address. HARICA said the flaw was introduced in the REST API offered by the HARICA RA on 2025-01-08 09:24 and affected only mailbox-validated S/MIME certificates; other validation levels and other certificate types were not impacted. After reproducing the issue, HARICA stopped certificate issuance, developed and deployed an urgent patch to reinstate the missing email validation, and revoked five non-expired, non-revoked misissued certificates within 24 hours. HARICA also refactored the RA code to add a central checkpoint before S/MIME and TLS certificate issuance to ensure required validations are completed successfully, and to verify that pre-validated organization requests include all labels of the pre-validated base domain names. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it would close the incident on 23-Apr-2025 unless there were items to discuss.
- HARICA received a subscriber report about S/MIME mailbox-validated certificates being issued without proper email validation and stopped issuance while responding.
- HARICA deployed an urgent patch and revoked five misissued mailbox-validated S/MIME certificates within 24 hours.
- HARICA completed refactoring action items to add central validation checks and pre-validated organization domain label matching before issuance.
- Mozilla indicated it would close the bug on 23-Apr-2025 unless there were remaining discussion items.
- HARICA — HARICA described a preliminary incident report: a subscriber reported that a REST API flaw allowed mailbox-validated S/MIME certificates without proper email validation, and HARICA said it patched the issue and revoked five misissued certificates within 24 hours.
- HARICA — HARICA posted the full incident report with impact, timeline, and root cause analysis, including that the problematic code appeared only in mailbox-validated S/MIME certificates.
- HARICA — HARICA requested the next update be set for 2025-03-11 to provide progress on remaining action items.
- HARICA — HARICA provided a status update describing designs for central validation cross-checking before certificate issuance and central domain-label matching for pre-validated organizations.
- HARICA — HARICA reported that all pending action items were completed as of 2025-03-21 and asked to close the incident.
- HARICA — HARICA posted an incident report closure summary stating the patch and revocations were completed and that the RA code was refactored to add central validation and pre-validated domain label checks.
- Mozilla representative — Mozilla stated it would close the bug next Wednesday, 23-Apr-2025, unless there were items to discuss.