Hi Adriano.
It was pointed out to me that the doppelganger intermediate certificates
that Actalis issued to Unicredit (https://crt.sh/?id=47081615 and
https://crt.sh/?id=147626411) don't quite meet Mozilla's current
"technically constrained" criteria.
Since v2.3, the Mozilla Root Store Policy has referenced BR 7.1.5, which
says (emphasis mine):
"If the Subordinate CA Certificate includes the id‐kp‐serverAuth
extended key usage, then the Subordinate CA Certificate MUST include the
Name Constraints X.509v3 extension with constraints on dNSName,
iPAddress *and DirectoryName*".
(In v2.2, "technically constrained" was defined within the Mozilla
policy itself, and that definition did not require a DirectoryName
constraint).
I suspect that the DirectoryName constraint requirement was added to the
BRs due to Windows XP's weird behaviour when processing a Name
Constraints extension that lacks a DirectoryName constraint (see
https://unmitigatedrisk.com/?p=201).
I've just adjusted my crt.sh code to enforce the DirectoryName
constraint requirement, and so the two Unicredit intermediates now
appear under https://crt.sh/mozilla-disclosures#undisclosed
On 04/10/17 13:33, Adriano Santoni via dev-security-policy wrote:
Nick,
I think I have addressed this in my reply to Rob Stradling a few minutes
ago.
In short: no, the "temporary unconstrained subCA" does never exist as a
signed document, only the final (constrained) subCA is signed.
Adriano
Il 02/10/2017 20:57, Nick Lamb via dev-security-policy ha scritto:
The "post-processing" element is confusing, and could do with a bit
more explanation unless perhaps I'm the fool here and everybody else
(m.d.s.policy regulars) understands how this works
Since the name constraints are part of the signed document, altering
them after it's signed would invalidate the signature. So surely that
can't be what happens.
On the other hand, if the thing being "post-processed" is a
tbsCertificate rather than a signed certificate surely that can be
created using whatever processes are convenient entirely outside the
protected physical environment and prior to the ceremony commencing?
At most it may be appropriate for the serial number to be chosen
during the protected process, to assure auditors that this was random
rather than chosen by a third party.
I guess the thing I'm seeking clarity on is whether a "temporary
unconstrained subCA" actually exists as a signed document, even
momentarily within the protected physical environment, and if so, how
that could possibly be necessary. Regardless of whether that's the
case, the proposed remedial actions are appropriate, but if there are
sketchy "temporary" unconstrained subCAs being created (and hopefully
destroyed) then it seems important to emphasise to other CAs that this
is not an acceptable practice.
--
Rob Stradling
Senior Research & Development Scientist
COMODO - Creating Trust Online
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy