Apple: Public Key Reuse
Apple reported a certificate issuance incident after identifying a race condition in its certificate issuance systems. Apple stated that the race condition could cause multiple certificates to be issued for the same public key when issuance requests are made simultaneously (or within a very small time period). Apple said 47 certificates were impacted in the preliminary report and later stated 44 certificates were impacted in the full incident report, and that all impacted certificates were revoked. Apple also reported that it partially stopped issuance by reaching out to the affected customer to stop approving certificates while a fix was worked on, and determined it was not necessary to stop all issuance due to low volume and mitigation of the primary group. Apple described remediation including implementing a two-stage database transaction for public key use, adding alerting for public key reuse errors, and updating its CPS. Apple requested closure after stating that the action items were completed and that remediation was sufficient to prevent a similar issue in the future.
- Apple updated its Apple Public CPS to version 5.0 with a statement in Section 4.6 about not providing certificate renewal that includes reuse of a public key.
- Apple identified a race condition in its certificate issuance systems that could lead to multiple certificates being issued for the same public key.
- Apple revoked the impacted certificates after identifying the incident.
- Apple published a preliminary incident report to Bugzilla and updated RA hosts with a fix for the key reuse race condition.
- Apple published the full incident report with timeline, root cause analysis, and impact details.
- Apple posted a report closure summary stating remediation and action items were completed and requested closure.
- Apple representative — Apple provided a preliminary incident report describing a race condition that could issue multiple certificates to the same public key and stated impacted certificates were revoked.
- Community commenter — A community member asked about encouraging CA adoption of narrower voluntary policies than the BRs and commented on transparency.
- Mozilla representative — Mozilla responded that the process can discourage voluntary higher standards and suggested alternative channels/resources such as the Mozilla wiki.
- Apple representative — Apple posted the full incident report with impact (44 certificates), timeline, root cause analysis, and remediation steps including a fix to RA hosts.
- Apple representative — Apple stated it was working toward a final action item and asked to set the next update date to 4/28/2025.
- Apple representative — Apple updated a chart showing completed action items including implementing fixes, adding automated alerting, and completing a CPS update.
- Apple representative — Apple posted a report closure summary stating remediation was completed (two-stage database transaction, alerting, and CPS update) and requested closure.
- CCADB representative — CCADB issued a final call for comments/questions and noted the incident would be closed if no further input was received.
- Google representative — Google commented that the report adhered to CCADB IRGs and praised the self-reporting transparency and proactive accountability.