Re: Mis-issuance of certificate with https in CN/SAN

2018-05-09 Thread Rob Stradling via dev-security-policy
On 16/03/18 10:27, Rob Stradling via dev-security-policy wrote: On 16/03/18 05:17, Jakob Bohm via dev-security-policy wrote: Please see https://crt.sh/?id=353098570=cablint Note: This is the CT precertificate. Note 2: According to crt.sh, the OCSP response for this precertificate is not

RE: Mis-issuance of certificate with https in CN/SAN

2018-03-23 Thread Ben Wilson via dev-security-policy
Matt and Jakob, Cybertrust Japan asked me to relay the following response to the list. Jakob, thank you very much for pointing this out. We should have reported this link, https://crt.sh/?id=357203958=cablint Matt, thank you very much also for asking about our remediation actions we did and

Re: Mis-issuance of certificate with https in CN/SAN

2018-03-20 Thread Matt Palmer via dev-security-policy
On Fri, Mar 16, 2018 at 04:28:10AM +, Ben Wilson via dev-security-policy wrote: > 7. List of steps your CA is taking to resolve the situation and ensure > such issuance will not be repeated in the future, accompanied with a > timeline of when your CA expects to accomplish these things. > >

Re: Mis-issuance of certificate with https in CN/SAN

2018-03-16 Thread Rob Stradling via dev-security-policy
On 16/03/18 05:17, Jakob Bohm via dev-security-policy wrote: Please see https://crt.sh/?id=353098570=cablint Note: This is the CT precertificate. Note 2: According to crt.sh, the OCSP response for this precertificate is not correct.  (error message: "OCSP response contains bad number of

Re: Mis-issuance of certificate with https in CN/SAN

2018-03-15 Thread Jakob Bohm via dev-security-policy
On 16/03/2018 05:28, Ben Wilson wrote: This mis-issuance incident was reported by Cybertrust Japan (CTJ), an intermediate CA of DigiCert. (https://bugzilla.mozilla.org/show_bug.cgi?id=1445857) Here's the incident report: 1.How your CA first became aware of the problem (e.g. via a

Mis-issuance of certificate with https in CN/SAN

2018-03-15 Thread Ben Wilson via dev-security-policy
This mis-issuance incident was reported by Cybertrust Japan (CTJ), an intermediate CA of DigiCert. (https://bugzilla.mozilla.org/show_bug.cgi?id=1445857) Here's the incident report: 1.How your CA first became aware of the problem (e.g. via a problem report submitted to your Problem