← DigiCert cases
Bugzilla #1389172
Certificate Problem Report
DigiCert: Certificate Issues Identified on the Mailing List
RESOLVED
DigiCert
AI Summary
DigiCert identified multiple certificate issues through community reports, including insufficient serial number entropy and metadata in the OU field. The company has taken steps to revoke affected certificates and patch their systems to prevent future occurrences. Key actions include revoking certificates from InfoCert and Siemens, and implementing stricter controls on certificate issuance. The case highlights the importance of compliance with industry standards and proactive remediation.
Chronology
- Initial report of certificate issues
- DigiCert patched systems to prevent metadata in OU field
- Planned revocation of Siemens Sub CA
- Timeline for remediation and compliance established
Participants
Jeremy Rowley
Kathleen Wilson
Ben Wilson
Ryan Sleevi
External References
Similar Local Cases
DigiCert / CTJ: Metadata in OU fields, Reserved IP Address
DigiCert / InfoCert: Insufficient Serial Number Entropy
DigiCert: Failure to revoke key-compromised certificates within 24 hours
DigiCert: no subject alternative name in Siemens certs
DigiCert: OCSP responder returning invalid responses
DigiCert: Non-BR-Compliant OCSP Responders
DigiCert: Random value in CNAME without underscore prefix
Digicert: Government Entity listed instead of registration number