eMudhra emSign PKI Services: Policy Document Inconsistency
eMudhra Technologies Limited reported an incident involving the issuance of a TLS certificate for CN=msmeranchi.nic.in with an RSA key size of 4048 bits. This issuance was based on a CSR from the subscriber and was compliant with the CA/Browser Forum Baseline Requirements, which only specify a minimum key size of 2048 bits. However, the CA's Certificate Policy/Certification Practice Statement (CP/CPS) versions v1.14 and v1.19 only referenced RSA 2048, leading to ambiguity regarding larger key sizes. The issue was identified by an external researcher on June 19, 2025, prompting eMudhra to acknowledge the inconsistency and plan corrective actions, including updating their CP/CPS to clarify acceptable key sizes. All 449 unexpired certificates that did not comply with the updated policy were subsequently revoked. The CP/CPS was revised and published on July 8, 2025.
- Certificate issued for CN=msmeranchi.nic.in with an RSA key size of 4048 bits.
- External researcher reported the issue regarding key size documentation.
- Non-compliance period ended with the initiation of remediation.
- Revised CP/CPS v1.20 published to clarify acceptable RSA key sizes.
- Final call for comments on the incident report before closure.
- Emudhra representative — Preliminary incident report submitted detailing the inconsistency in key size documentation.
- Sectigo — Provided feedback on the need for clarity in documentation regarding key sizes.
- Emudhra representative — Confirmed that all unexpired certificates identified in the incident were revoked.
- CCADB representative — Final call for comments on the incident report before closure.