HARICA: S/MIME certificate issuance with incorrect commonName
HARICA reported a self-discovered incident in which a recently deployed S/MIME SV certificate issuance workflow populated the certificate subject `commonName` with the `organizationName` value instead of the concatenation of `givenName` and `surname`. HARICA became aware of the issue on 2025-01-22 after receiving an email from a subscriber who used the new “bulk Enterprise S/MIME SV certificate request” process and observed the incorrect `commonName`. HARICA suspended S/MIME certificate issuance until a patch was deployed on 2025-01-23, after which issuance resumed. HARICA identified 68 mis-issued certificates (43 non-expired, non-revoked) and revoked affected certificates, with a note that delayed revocation for some remaining certificates was handled in a separate bug (Bug 1945389). HARICA also implemented remediation including additional unit tests and added realistic test vectors to the test process. Mozilla indicated it would close the bug after follow-up questions, and HARICA requested closure via an incident closure summary.
- HARICA discovered that SV S/MIME certificates were issued with an incorrect subject commonName value due to a flaw in the bulk issuance workflow.
- HARICA deployed a patch fixing the workflow and resumed SV S/MIME certificate issuance.
- HARICA informed subscribers of upcoming revocation for affected active certificates.
- HARICA revoked remaining affected certificates, with delayed revocation issues addressed in a separate bug.
- HARICA completed adding realistic test vectors to the test process.
- HARICA completed unit test implementations for SV S/MIME commonName correctness.
- HARICA submitted an incident closure summary requesting closure of the bug.
- HARICA — Filed a preliminary incident report describing the incorrect commonName behavior, issuance suspension, planned revocation, subscriber notification, and a commitment to post a full incident report by 2025-01-31.
- HARICA — Posted the full incident report with root cause analysis, impact (68 mis-issued certificates; 43 scheduled for revocation within 5 days), the timeline, and lessons learned including that some certificates were not revoked by the pre-determined timeline.
- HARICA — Reported preparation of internal documentation requiring realistic testing values.
- HARICA — Confirmed completion of internal documentation with realistic testing values and updated action items and due dates.
- HARICA — Provided a status update that unit tests for commonName correctness were being prepared and requested setting the next update to 2025-04-01.
- HARICA — Reported completion of all pending action items and asked to close if there were no further questions.
- Mozilla representative — Asked whether there were follow-up questions or requests and indicated HARICA should file an incident closure summary to close the bug.
- HARICA — Submitted an incident report closure summary, stating remediation steps (revocation and subscriber contact) and requesting closure; noted delayed revocation for remaining certificates was separately addressed in Bug 1945389.
- Mozilla representative — Indicated the bug would be closed next Wednesday (23-Apr-2025) unless there were questions or issues.