On 03/10/17 17:50, Kathleen Wilson via dev-security-policy wrote:
On Friday, September 29, 2017 at 1:29:26 PM UTC-7, Rob Stradling wrote:
Several CAs have issued intermediate CA certificates with duplicate
serial numbers. This is a clear violation of the serial number
uniqueness requirement of the BRs and RFC5280 4.1.2.2. Below is a list
of all those known to crt.sh that chain to at least 1 NSS built-in root:
Thanks, Rob. I plan to file Bugzilla Bugs for these (for those not already
filed), and request that these CAs scan their databases for all certs with same
issuer/serial and provide an incident report.
But before doing so, I compared your finding with what I see in the CCADB...
<snip>
Issuer: https://crt.sh/?caid=1450
Issuer O: WoSign CA Limited
Issuer CN: CA 沃通根证书
Subject CN: 中国湖南 EV 服务器证书
Serial #: 44:80:7b:20:7c:f2:05:2e:8d:34:11:77:02:66:d2:95
Certs: https://crt.sh/?id=7841622
https://crt.sh/?id=9318242
Revoked?: No (x-certs from StartCom not yet in OneCRL; StartCom roots
still in NSS)
Subject CN: CA 沃通 EV 代码签名证书
Serial #: 3a:de:c4:02:27:0b:f4:ee:9e:89:2c:c6:5e:0a:da:21
Certs: https://crt.sh/?id=12728869
https://crt.sh/?id=12729072
Revoked?: No (x-certs from StartCom not yet in OneCRL; StartCom roots
still in NSS)
I don't plan to file a bug for these WoSign doppelganger certs, since we've
already disabled and are removing the WoSign roots (bug #1387260).
That seems reasonable. I realize the old WoSign and StartCom roots are
already (semi-)disabled in Firefox, but since they've not yet been
removed from NSS I considered them to be in scope for this report (for
the benefit of any other consumers of the NSS trust list).
Also, I see another set of dobbelganger certs in the CCADB. Not sure why they
didn't show up in your script output...
Issuer commonName: Belgium Root CA4
Subject commonName: Belgium Root CA4
Serial Number: 4f33208cc594bf38
https://crt.sh/?id=26311649
https://crt.sh/?id=160110886
Revoked? No
My query did find those two "Belgium Root CA4" certs, but (rightly or
wrongly) I decided to omit them from my report. They're both
self-signed root certs rather than intermediates, although there are
other trust paths from the "Belgium Root CA4" CA up to a root that's
included in NSS.
FWIW, I also found one other pair of self-signed root certs that share a
serial number, although there are no longer any known unrevoked trust
paths from this CA up to a root that's included in NSS:
Issuer commonName: Common Policy
Subject commonName: Common Policy
Serial Number: 29:36:47:aa:e3:8a:ac:86:4a:23:56:f2:ca:b7:61:af
Certs: https://crt.sh/?id=20444
https://crt.sh/?id=26310636
--
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online
Office Tel: +44.(0)1274.730505
Office Fax: +44.(0)1274.730909
www.comodo.com
COMODO CA Limited, Registered in England No. 04058690
Registered Office:
3rd Floor, 26 Office Village, Exchange Quay,
Trafford Road, Salford, Manchester M5 3EQ
This e-mail and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they are
addressed. If you have received this email in error please notify the
sender by replying to the e-mail containing this attachment. Replies to
this email may be monitored by COMODO for operational or business
reasons. Whilst every endeavour is taken to ensure that e-mails are free
from viruses, no liability can be accepted and the recipient is
requested to use their own virus checking software.
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy