DigiCert: Mis-Issuance Rekey certificates
DigiCert reported a misissuance incident involving 1,090 rekeyed certificates that were issued using expired domain validation documents. The issue was discovered during a routine internal review on September 14, 2017, leading to an immediate investigation and a system patch to prevent further misuse of expired documentation. DigiCert has since reverified 1,021 of the affected domains and revoked five certificates that could not be revalidated. The CA is committed to revoking any remaining certificates that do not pass revalidation by the end of the week. The incident has been resolved with all certificates logged to CT and system updates implemented to prevent future occurrences.
- DigiCert discovered the misissuance during a routine internal review.
- DigiCert patched the system to prevent further rekeying with expired validation documents.
- DigiCert revoked five certificates that could not be revalidated.
- DigiCert completed system updates and remediated all certificates.
- DigiCert — DigiCert reported the misissuance and outlined the steps taken to address the issue.
- Community commenter — Inquired about the root cause and communication issues related to the misissuance.
- DigiCert — Confirmed that all certificates have been added to the CT database.
- Fastly representative — Closed the case after confirming all certificates were remediated and system updates were in place.