Fina mis-issued test certificates for IP addresses and test-named domains, then remediated and closed the incident
Fina self-reported an incident involving mis-issued TLS/SSL OVCP certificates from Fina RDC 2020. The issue was first triggered by a notice from Microsoft’s Trusted Root Program about certificates containing SAN iPAddress 1.1.1.1, and Fina later acknowledged an additional mis-issued certificate for 2.2.2.2 and other certificates with test-prefixed domain names. Fina said the affected certificates were issued only as internal test certificates for production-environment testing, that the corresponding private keys stayed within the CA environment, and that the certificates were revoked and issuance of such test certificates was stopped. Fina also revised its CPS/procedures, completed employee training, added linting, and carried out an extraordinary external full audit. In the closure report, Fina stated that all action items were complete and requested closure of the incident.
- Fina began issuing internal test certificates that included SAN IP address 1.1.1.1.
- Fina revoked the reported affected certificates and stopped issuing internal test certificates.
- Fina published a new CPS version stating that all certificates issued on the production system are considered subscriber certificates.
- Fina received the Conformity Assessment Report and audit attestation letter from the external CAB.
- Fina submitted a closure report stating the incident was resolved and all action items were complete.
- Fina representative — Fina filed a preliminary incident report saying Microsoft had notified it about mis-issued certificates for 1.1.1.1, that three reported certificates were revoked, and that further issuance of those internal test certificates had been stopped.
- Heise representative — Christopher Kunz noted an additional certificate for 2.2.2.2 and questioned the revocation reason used.
- Fina representative — Fina confirmed it had informed Oracle about the 2.2.2.2 certificate and said the certificate and private key were used only for internal testing and the private key was destroyed.
- Fina representative — Fina submitted a full incident report with a timeline, impact count of 13 affected certificates, and a statement that issuance had been stopped.
- Fina representative — Fina said the investigation initially focused on the 1.1.1.1 and 2.2.2.2 certificates, and that it was also investigating certificates with reserved IPs, internal names, and non-LDH labels.
- Fina representative — Fina posted action items, including banning issuance of such certificates, training, a new CPS version, a new testing procedure, and internal and external audits.
- Fina representative — Fina said it planned to use ZLint and explained that it was working to establish linting with its current software and a future ECC-based infrastructure.
- Fina representative — Fina reported completion of employee training and receipt of the external audit report and attestation letter, which it forwarded to the Croatian supervisory body.
- Fina representative — Fina filed a closure report stating that all planned action items were complete and that it believed the incident was resolved.