DigiCert: BR 3.2.5 Validation of Authority Failure for OV Certs
DigiCert reported a compliance failure regarding the validation of OV certificate requests due to a bug in their OEM integration. This issue allowed the use of constructed email addresses for authenticity verification, which did not meet the required standards. The problem was discovered by TBS Internet on December 30, 2017, and DigiCert took immediate action to disable email verification and began revalidating affected certificates. A total of 5,067 certificates were identified as potentially problematic, with 3,437 organizations impacted. As of June 2, 2018, DigiCert had completed the remediation process, revoking 35 certificates that could not be validated.
- DigiCert received a report about the validation issue.
- DigiCert disclosed the incident to Mozilla.
- DigiCert completed the remediation process.
- Fastly representative — Tim Hollebeek from DigiCert posted the incident report detailing the validation failure.
- DigiCert — Revalidation is ongoing, and a timeline is being established.
- DigiCert — DigiCert finished the remediation of the affected certificates.