← Apple Inc. cases
Bugzilla #1955365
Certificate Problem Report
Apple: Public Key Reuse
RESOLVED
FIXED
Apple Inc.
AI Summary
Apple identified a race condition in its certificate issuance systems that allowed multiple certificates to be issued for the same public key when requests were made simultaneously. This issue affected 44 certificates, all of which were revoked promptly. The incident was self-reported, and Apple has since implemented a two-stage database transaction to prevent future occurrences. The company updated its Certificate Policy Statement to reflect these changes and has committed to improved detection mechanisms for similar issues.
Chronology
- Race condition identified in certificate issuance systems.
- Preliminary Incident Report published.
- CPS updated to remove conflicting statements.
- Report Closure Summary published.
Participants
certification_authority@apple.com
rowleylaw@gmail.com
bwilson@mozilla.com
incident-reporting@ccadb.org
chrome-root-program@google.com
External References
Similar Local Cases
Apple: Revocation Delay for TLS certificates issued outside the TTL of the CAA record
Apple: EV Certificate Approver Authorization
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
Apple: TLS certificates issued outside the TTL of the CAA record
Apple: OCSP availability 2020-11-12
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
Apple: CRLs for dormant CAs will not be populated in CCADB
Apple: Test website certificates expired