Users of Barclays Bank’ mobile application have been left without the possibility to pay for purchases due to legacy intermediate SSL-certificate
On a Thanksgiving Day, November 24, 2016 an emergency has occurred. Customers of Barclays Bank, which were users of mobile banking application, were unable to perform any transactions due to pinning the outdated intermediate certificate in the application. Barclays has immediately appealed to Symantec who was a certificate issuer with a request for a new certificate for * .payliquid.com, tied to the old intermediate CA.
Symantec stated that it is possible; however, it will require issuing a certificate with the consecutive serial number, which contradicts with CA / B Forum Baseline Requirements Section 7.1. The certificate was issued in the old system, which has been replaced because it supported only issuance of certificates with the sequential serial numbers.
According to the statement from representatives of Barclays, «recent change in intermediate certificate had a negative impact on the Barclays’ SSL-pinning. As a result, the connection to the mobile application for all of our users will fail. The only way to solve this problem requires us to change our iOS and Android application code. It will take several weeks, including security testing, send app to the store, validation and deploy. "
The overall impact of this issue is quite serious and will affect mainly small and medium-sized enterprises, which are the Barclays customers and accepting payments using devices that link to the application.
Several thousands of customers of small and medium-sized businesses, operating mostly in the UK market, will not be able to perform any transactions from 8.30 a.m. 25/11/16 on a "Black Friday" and during the holiday shopping period. This will affect hundreds of thousands of customer's transactions, until the application is updated, and then released again.
Due to the severity of the issue and a potential huge negative impact on customers during a long period of holiday shopping, Symantec issued a new certificate on the evening of November 24 to replace the old one. This certificate has a short period, and published in the CT logs.
Should you require a modern Symantec SSL-certificate, you can always purchase them in our store at competitive prices with no hassle.