DigiCert / Wells Fargo: Invalid DNS names
This case involves DigiCert's disclosure of compliance issues related to invalid DNS names associated with certificates issued for Wells Fargo. The issues included a reserved domain name and a certificate with trailing whitespace. DigiCert became aware of these problems through a certificate problem report and subsequent discussions. They took corrective actions, including revoking the affected certificates within 24 hours and addressing OCSP response issues. The CA confirmed that they have ceased issuing certificates with these problems and have implemented measures to prevent recurrence. The case has been resolved with the issuing CA now revoked.
- Invalid DNS name submitted as a certificate problem report.
- Certificate was revoked within 24 hours of the report.
- Decision made to discontinue operating the Wells Fargo Sub CA.
- The issuing CA has now been revoked.
- Mozilla representative — This bug has been separated out from Bug #1389172 to request an incident report specific to this subCA.
- DigiCert — The invalid DNS name issue was submitted as a cert problem report on Aug 14th, 2017.
- Community commenter — Important to understand why the OCSP responders were serving improper responses.
- DigiCert — A call was held on Sep 5 to discuss discontinuing the Wells Fargo Sub CA.
- DigiCert — The issuing CA has now been revoked. Can we close the bug?