DigiCert / CTJ: Metadata in OU fields, Reserved IP Address
This case involves DigiCert's subCA, CTJ, which disclosed issues related to metadata in Organizational Unit (OU) fields and the use of reserved IP addresses in certificates. The CA identified that metadata was improperly included in OU fields and that a certificate containing a reserved IP address had not been revoked in a timely manner. CTJ implemented a patch to prevent issuance of certificates with metadata in the OU field and updated its procedures to ensure compliance with the Baseline Requirements. The CA has confirmed that it has ceased issuing certificates with these issues and is migrating to a new system to enhance compliance. The case is now resolved.
- CTJ systems patched to prevent metadata in OU fields.
- CTJ updated procedures for revocation of certificates with reserved IP addresses.
- Mozilla representative — Requested an incident report specific to CTJ regarding metadata in OU fields and reserved IP addresses.
- DigiCert — Provided details on the CA's awareness of the issues and remediation steps taken.
- SECOM Trust Systems CO., LTD. — Confirmed that CTJ has patched its system to prevent issuance of certificates with metadata.
- SECOM Trust Systems CO., LTD. — Announced integration of pre-issuance checking into the issuance pipeline.