Menu
Comodo fixes bug that led to issue of banned digital certificates

Comodo fixes bug that led to issue of banned digital certificates

The company issued new certs for internal hosts, which is now banned by the CAB Forum

Comodo said Monday it fixed a bug that led to the issuance of some now-banned digital certificates. Other CAs might have the same problem, too.

Under new rules from the CA/Browser Forum (CAB) that came into force on Nov. 1, certification authorities (CAs) are not supposed to issue new SSL/TLS (Secure Sockets Layer/Transport Layer Security) certificates for internal host names.

Comodo had been preparing for the rule change, but a "subtle bug" was introduced in its issuing system on Oct. 30, wrote Rob Stradling, senior research and development scientist, in a post on the CAB Forum.

"Despite our code review and QA processes, this bug still made it into production code," Stradling wrote.

The result was that eight certificates ended up being issued which shouldn't have, and those certificates have now been revoked, he wrote.

Other CAs may have had the same problem. Stradling wrote that "we found non-compliant certificates issued by quite a number of other CAs, but I'll document these in another post."

The reason why CAs aren't supposed to issue SSL/TLS certificates for internal hosts is to prevent man-in-the-middle attacks.

Companies and organizations have traditionally bought SSL/TLS certificates for servers or devices with internal host names that can't be seen from the public Internet.

Those certificates are used to authenticate the machines that are talking to each other. But since organizations aren't CAs themselves, they've had to buy those certificates from CAs.

While CAs validate request for digital certificates for public domains to ensure the right entity is requesting one, they can't do that for internal hosts.

That makes it possible for an attacker to obtain a digital certificate for a server with a generic name such as "local.host," and then use it in an attack to monitor encrypted data traffic of another organization.

By October 2016, CAs are supposed to revoke certificates for internal hosts if those certificates have not yet expired.

Stradling wrote that a hot fix was distributed about two hours after Comodo discovered the problem.

"We regret that our implementation of this important and long-trialed policy change fell below the standards that are expected of us and that we expect of ourselves," Stradling wrote.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Brand Post

What to expect from your IT Distributor

Whether you’re just starting out or you’ve been around since before the dot com rollercoaster, choosing the right distribution partner can be a pivotal factor in your success. This definitive guide outlines the traits that every IT partner needs to look for in their IT Distributor.

Featured

Slideshows

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners

More than 500 channel leaders gathered in Auckland on 21 October at the ​Reseller News Innovation Awards ​2020 to celebrate the achievements of the New Zealand technology industry's top partners, start-ups, vendors, distributors and individuals.

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners
Meet the winners of the 2020 Reseller News Innovation Awards

Meet the winners of the 2020 Reseller News Innovation Awards

Reseller News honoured the standout players of the New Zealand channel in front of more than 500 technology leaders in Auckland on 21 October, recognising the achievements of top partners, start-ups, vendors, distributors and individuals.

Meet the winners of the 2020 Reseller News Innovation Awards
Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

This year’s Reseller News 30 Under 30 Tech Awards were held as an integral part of the first entirely virtual Emerging Leaders​ forum, an annual event dedicated to identifying, educating and showcasing the New Zealand technology market’s rising stars. The 30 Under 30 Tech Awards 2020 recognised the outstanding achievements and business excellence of 30 talented individuals​, across both young leaders and those just starting out. In this slideshow, Reseller News honours this year's winners and captures their thoughts about how their ideas of leadership have changed over time.​

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners
Show Comments