Hi Rob,

sorry for the slight delay; see my answers below:


Il 02/10/2017 17:03, Rob Stradling via dev-security-policy ha scritto:
Hi Adriano.  Thanks for providing your incident report so promptly.

Some questions inline...

On 02/10/17 15:26, Adriano Santoni via dev-security-policy wrote:
<snip>
6) Explanation about how and why the mistakes were made or bugs introduced, and how they avoided detection until now.

In the particular case of the generation of technically constrained SubCA certificates, and only in that particular case, we use a special procedure that operates in two phases: first, we generate a temporary unconstrained SubCA certificate using our core Root CA software;

Are these "temporary unconstrained SubCA certificate"s publicly trusted?  That is, do they have valid signatures from your "Actalis Authentication Root CA" (https://crt.sh/?caid=935) ?
If yes, can you confirm that you have disclosed them all to the CCADB?
No. The temporary unconstrained SubCA certificate is not trusted, because it is post-processed when it still is a tbsCertificate. When it comes into existence as a signed object, it already is a technically constrained certificate. As such, it is not required to disclose it to the CCADB.


Since it had been Unicredit itself to ask for regeneration of their SubCA certificate, on the very same day, our staff assumed that the first SubCA certificate would have been discarded; but apparently, due to some misunderstanding within Unicredit, it was mistakenly installed on some sites and then removed, but it probably remained online long enough for some crawler to detect it.

Are you suggesting that "discarding" a certificate makes it acceptable to reuse the same serial number in another certificate?
I am not suggesting anything like that. Our operating instructions implied that post-processing would be executed only once, but the post-processing software module in itself did not prevent a second run. Due to the fact that it was the first time we had to perform such task, and because the operating instructions did not expressly prohibit that, our staff mistakenly decided to trigger a second run in order to update the same certificate upon receiving, unexpectedly, an updated list of domains from Unicredit on that same day without notice. Unfortunately, on that occasion, the result of the first run had been already sent to Unicredit.

- revocation of the affected SubCA certificate is scheduled for Oct 4th, EOB.

Nit: revocation of *both* affected SubCA certificates, since they share the same serial number.

Yes.

----
Adriano Santoni
ACTALIS S.p.A.



Attachment: smime.p7s
Description: Firma crittografica S/MIME

_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to