Skip to content

Publish the certificate thumbprints for DigiCert Federal SSP Intermediate CA - G6 - #2085

Open
arpitjain099 wants to merge 1 commit into
GSA:stagingfrom
arpitjain099:fix/g6-thumbprints
Open

arpitjain099 wants to merge 1 commit into
GSA:stagingfrom
arpitjain099:fix/g6-thumbprints

Conversation

@arpitjain099

Copy link
Copy Markdown

The "DigiCert Federal SSP Intermediate CA - G6" row on the Distribute FCPCA page publishes hashes of the PEM file rather than thumbprints of the certificate.

Taking the .cer the row links to and hashing it both ways:

certificate (DER of the parsed cert)  sha1 0dd44fd015c1f76327be46661456ce8f6fb346ec
                                    sha256 72653e7e...c054686e
file bytes as shipped                 sha1 806b3aa2dbeb6a097bf07920bb77bb1eb9fbb2dd
                                    sha256 ac309ffe...d71a773b

The second pair is what the page currently shows. The file is PEM, so the two differ.

The convention on the page is the thumbprint: of the PEM certificates under _implement/certs, three publish the certificate thumbprint and this row is the only one that does not. The certificate itself is fine, its serial and validity match the rest of the row, so it is the table that is off.

An admin comparing what Windows shows against this page sees a mismatch on a genuine certificate. It fails safe, since the reaction is to decline, but the page is what they are checking against.

…iate CA - G6

The SHA-1 and SHA-256 values in that row are hashes of the PEM file rather
than of the certificate. The shipped .cer parses to thumbprints
0dd44fd015c1f76327be46661456ce8f6fb346ec and
72653e7e6aa246b778a07592b4cf09e2b4f629e45994e289090f84d5c054686e. Of the PEM
certificates under _implement/certs, this is the only row that publishes the
file hash; the rest publish the thumbprint.

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant