-
Notifications
You must be signed in to change notification settings - Fork 136
Draft Ballot SC-XX: Improve Certificate Problem Reports and Clarify the Meaning of Revocation #622
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
270572f
a37126e
c704cd0
4a6b8ce
bd57535
ab72e67
7612e9d
5c81321
df07211
31a6479
be40b46
342ff48
65085bd
4bb06c1
594427d
91f8e5e
4e43a30
cf05e90
332ac9e
a2a51e2
b4bb5c5
9093e46
9642e7b
0b97d0d
0f2553b
c32f356
ef4e201
f0b7e46
2ad1582
f010ab1
fb938d0
572ee86
9db978c
8193abc
53df8aa
339b88d
90856b8
2840471
d25aa9b
d7c86f8
267cdf4
9112942
6cf96bd
d4df4e7
4751419
bcee0b8
a0722b0
ef1dda7
a45b4ac
c0231eb
2390397
9ac300c
4285aa5
4a97edf
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -485,6 +485,10 @@ The script outputs: | |||||||||
|
|
||||||||||
| [https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml](https://www.iana.org/assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml) | ||||||||||
|
|
||||||||||
| **Revoked**: Effective 2027-02-15, the following conditions must be met for a Certificate to be considered revoked: | ||||||||||
| - if the Certificate contains a CRL Distribution Point URI: any request to that URI for the CRL (regardless of network perspective or serving endpoint) returns a CRL containing the Certificate's serial number. | ||||||||||
| - if the Certificate contains an Authority Information Access OCSP URI: any OCSP request to that URI for the Certificate's serial number (regardless of network perspective or serving endpoint) results in a response with a `certStatus` value of `revoked`. | ||||||||||
|
|
||||||||||
| **Reverse Zone Domain Name**: the FQDN in the `.arpa` namespace that corresponds to an IP address. This FQDN is constructed by converting the IP address to a sequence of labels followed by the applicable IP Reverse Zone Suffix, as specified in RFC 1035 (for IPv4 addresses) and RFC 3596 (for IPv6 addresses). | ||||||||||
|
|
||||||||||
| **Root CA**: The top level Certification Authority whose Root Certificate is distributed by Application Software Suppliers and that issues Subordinate CA Certificates. | ||||||||||
|
|
@@ -1632,19 +1636,48 @@ The Subscriber, RA, or Issuing CA can initiate revocation. Additionally, Subscri | |||||||||
|
|
||||||||||
| ### 4.9.3 Procedure for revocation request | ||||||||||
|
XolphinMartijn marked this conversation as resolved.
|
||||||||||
|
|
||||||||||
| The CA SHALL provide a process for Subscribers to request revocation of their own Certificates. The process MUST be described in the CA's Certificate Policy or Certification Practice Statement. The CA SHALL maintain a continuous 24x7 ability to accept and respond to revocation requests and Certificate Problem Reports. | ||||||||||
| Prior to 2027-02-15, for Section 4.9.3 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.2.5 of the Baseline Requirements for TLS Server Certificates. Effective 2027-02-15, the CA SHALL adhere to these Requirements. | ||||||||||
|
|
||||||||||
| The CA's Certificate Policy or Certification Practice Statement MUST describe a process for Subscribers to request revocation of their own Certificates. | ||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Including this info in a standalone CP isn't appropriate; that document places requirements on CAs, not communicates about how CAs fulfill requirements. A description of a CA's revocation process belongs in a CPS, not a CP.
Suggested change
|
||||||||||
|
|
||||||||||
| The CA SHALL maintain highly available systems to accept revocation requests and Certificate Problem Reports, and the personnel and procedures to meet the response deadlines specified in these Requirements. | ||||||||||
|
|
||||||||||
| The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for submitting Certificate Problem Reports. The CA SHALL publicly disclose the instructions in Section 1.5.2 of their CPS and SHOULD additionally disclose the instructions through readily accessible online means (e.g. a KB article, dedicated webpage, FAQ). | ||||||||||
|
|
||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. In response to discussion, consider adding something like
Suggested change
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Is the intent of this to remove the 24 hour investigation in section 4.9.5? Is there a thought that today a subscriber request is 24 hours to investigate + 24 hours to revoke? If so I think we should probably rework the sections in general to consolidate processing times to that section.
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
I’m not sure I follow - can you please explain? What 24-hour investigation period currently exists for Subscriber initiated revocation? I read 4.9.1.1 (“Reasons for Revoking a Subscriber Certificate”) to state that all Subscriber initiated revocation (e.g., points 1 and 2) must be completed within 24 hours from the time of request - there is no investigation period. While 4.9.5 (today) commingles Subscriber initiated revocation requests and Certificate Problem Reports, this proposed ballot attempts to separate them. I also read the 24 hour requirement in 4.9.5 to be specific only to Certificate Problem Reports - not Subscriber initiated revocation (mostly because of the “Within 24 hours after receiving a Certificate Problem Report” lead-in”).
Though addressed above - no, there is no thought that there’s a 24 hour investigation period for Subscriber initiated revocation requests. If a Subscriber initiates their own revocation (e.g., through a customer portal or using ACME) - it’s unclear what needs to be investigated. The proposed 24 hour investigation period is for Certificate Problem Reports (e.g., somebody reports via the CPS’ defined problem reporting mechanism “Your policy says X, your certificates do Y”) - where the CA Owner needs (and deserves) time to corroborate the claim and scope next steps. |
||||||||||
| Within twenty-four (24) hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to the report and determine if it's "actionable." | ||||||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. nit: s/receiving a/receiving a properly submitted and complete/
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I’d respectfully push back on this one, for a few reasons:
If the concern is that spam or malformed submissions shouldn't each start a 24-hour investigation, I'd rather address that in the "A CA MAY take measures to prevent submission of non-actionable Certificate Problem Reports..." sentence if you feel it’s not already covered. |
||||||||||
|
|
||||||||||
| A Certificate Problem Report is considered actionable if it includes: | ||||||||||
| 1. at least one valid identifier for a time-valid and unrevoked Certificate issued by the CA. The CA MUST support the use of a serial number and SHOULD support the use of a SHA-256 fingerprint of the Certificate and/or Precertificate as an identifier; and | ||||||||||
| 2. information about either: | ||||||||||
| - how the Certificate(s) in question violates these Requirements or a CA's own policies; or | ||||||||||
| - a reason for Certificate revocation (e.g., a demonstration of Key Compromise, or a Subscriber request aligned with [Section 4.9.1](#491-circumstances-for-revocation)). | ||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. In response to discussion:
Suggested change
|
||||||||||
|
|
||||||||||
| A CA MAY take measures to prevent submission of non-actionable Certificate Problem Reports (e.g., input control validation on a form used to collect Certificate Problem Reports), but MUST be able to receive actionable Certificate Problem Reports. | ||||||||||
|
|
||||||||||
|
XolphinMartijn marked this conversation as resolved.
|
||||||||||
| The CA SHALL provide Subscribers, Relying Parties, Application Software Suppliers, and other third parties with clear instructions for reporting suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates. The CA SHALL publicly disclose the instructions through a readily accessible online means and in Section 1.5.2 of their CPS. | ||||||||||
| Within twenty-four (24) hours after determining a Certificate Problem Report is actionable: | ||||||||||
|
XolphinMartijn marked this conversation as resolved.
|
||||||||||
| 1. The CA SHALL provide a report on its findings to the entity who filed the Certificate Problem Report, if contact details have been provided. | ||||||||||
|
XolphinMartijn marked this conversation as resolved.
|
||||||||||
| 2. The CA SHOULD provide a report on its findings to applicable Subscriber(s). | ||||||||||
|
XolphinMartijn marked this conversation as resolved.
|
||||||||||
| 3. If the CA determines the Certificate Problem Report requires an action of revocation for the Certificate(s) specified within, the CA SHOULD work with the applicable Subscriber to determine the date and time which the CA will revoke the Certificate. The period from the time the Certificate Problem Report was determined actionable to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). | ||||||||||
|
XolphinMartijn marked this conversation as resolved.
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||||||
|
|
||||||||||
| Within one-hundred-twenty (120) hours after determining a Certificate Problem Report is actionable, the CA MUST evaluate all time-valid and unrevoked Certificates issued by the CA to detect additional instances of the non-compliance described in the report. The period from the time the additional affected Certificates were first identified to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). | ||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. In response to the "3. Scope of “all time-valid and unrevoked Certificates issued by the CA”" question on list.
Suggested change
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. It feels like this section needs a carve-out for when the report is considered Actionable because it includes "a reason for Certificate revocation (e.g., a Subscriber request aligned with Section 4.9.1)". It's impossible for such a request to affect other certificates in the CA's valid corpus, so there should be no obligation for them to conduct a search. |
||||||||||
|
|
||||||||||
| Within twenty-four (24) hours after determining a Certificate Problem Report is not actionable, the CA MUST provide a report on its findings to the entity who filed the Certificate Problem Report if contact details have been provided and request the information necessary to satisfy the above requirements of an actionable Certificate Problem Report, unless the CA can reasonably claim the Certificate Problem Report is unrelated to the compliance or security of certificates it issued. | ||||||||||
|
|
||||||||||
| **Note**: If a non-actionable Certificate Problem Report is later amended by the reporter to satisfy the requirements of an actionable report described above, the time of receipt of the requested missing information is the basis for subsequent revocation timelines, if determined necessary. | ||||||||||
|
XolphinMartijn marked this conversation as resolved.
|
||||||||||
|
|
||||||||||
| ### 4.9.4 Revocation request grace period | ||||||||||
|
|
||||||||||
| No stipulation. | ||||||||||
|
|
||||||||||
| ### 4.9.5 Time within which CA must process the revocation request | ||||||||||
|
XolphinMartijn marked this conversation as resolved.
|
||||||||||
|
|
||||||||||
| Within 24 hours after receiving a Certificate Problem Report, the CA SHALL investigate the facts and circumstances related to a Certificate Problem Report and provide a preliminary report on its findings to both the Subscriber and the entity who filed the Certificate Problem Report. | ||||||||||
| Prior to 2027-02-15, for Section 4.9.5 of these Requirements, the CA SHALL adhere to these Requirements or Version 2.2.5 of the Baseline Requirements for TLS Server Certificates. Effective 2027-02-15, the CA SHALL adhere to these Requirements. | ||||||||||
|
|
||||||||||
| After reviewing the facts and circumstances, the CA SHALL work with the Subscriber and any entity reporting the Certificate Problem Report or other revocation-related notice to establish whether or not the certificate will be revoked, and if so, a date which the CA will revoke the certificate. The period from receipt of the Certificate Problem Report or revocation-related notice to published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). The date selected by the CA SHOULD consider the following criteria: | ||||||||||
| The period between receipt of a revocation request from the Subscriber and published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). If the request is not authenticated upon receipt, the CA SHALL within 24 hours of receipt work with the requester to authenticate the request, and the period listed above will be measured from the time of authentication. | ||||||||||
|
|
||||||||||
| The period between the determination that a Certificate Problem Report is actionable and published revocation MUST NOT exceed the time frame set forth in [Section 4.9.1.1](#4911-reasons-for-revoking-a-subscriber-certificate). | ||||||||||
|
|
||||||||||
| The date selected by the CA SHOULD consider the following criteria: | ||||||||||
|
|
||||||||||
| 1. The nature of the alleged problem (scope, context, severity, magnitude, risk of harm); | ||||||||||
| 2. The consequences of revocation (direct and collateral impacts to Subscribers and Relying Parties); | ||||||||||
|
|
@@ -1734,6 +1767,8 @@ No Stipulation. | |||||||||
|
|
||||||||||
| See [Section 4.9.1](#491-circumstances-for-revocation). | ||||||||||
|
|
||||||||||
| Effective 2027-02-15, the CA's Certificate Policy or Certification Practice Statement MUST describe the circumstances that necessitate the CA to (1) reject subsequent certificate requests containing a known compromised public key and (2) perform a cascading revocation of all unexpired and unrevoked certificates containing the same compromised public key when the revocation reason of a revocation is `keyCompromise`, | ||||||||||
|
|
||||||||||
| ### 4.9.13 Circumstances for suspension | ||||||||||
|
|
||||||||||
| The Repository MUST NOT include entries that indicate that a Certificate is suspended. | ||||||||||
|
|
||||||||||
Uh oh!
There was an error while loading. Please reload this page.