DigiCert: improper use of domain validation method
DigiCert reported that, after a customer requested information about the validation process for four domains, DigiCert investigated and found that the domains were not properly validated using a post-Aug 1 domain validation method. DigiCert said that when attempting to revalidate the domains prior to August 1, the random value was sent to an address other than the WHOIS contact, which led to a broader investigation into its revalidation efforts. DigiCert stated that from February through April 2018 it permitted some legacy Symantec customers to use Method 1, and that around April the process was modified to include a BR-compliant Random Value, effectively transforming the validation from Method 1 to Method 2. DigiCert reported that on August 13, 2018 it stopped all issuance based on the process that converted Method 1 validations to Method 2 validations, and that impacted certificates were under review (initially described as just under 2,500). In a later update, DigiCert stated that there were 1,233 certificates issued using the improper domain validation method and that remediation was underway via verifying control with the applicant or revoking. DigiCert ultimately reported that everything was revalidated and approved using a BR-compliant method and that, as suspected, exactly zero certificates were revoked; it also described plans to improve detection and prevention by reducing manual steps and restricting validation staff input, and by using machine learning to detect WHOIS-like documents.
- A customer requested information about DigiCert’s validation process for four domains, prompting DigiCert’s investigation.
- DigiCert stopped issuance based on the process converting legacy Method 1 validations to Method 2 validations.
- DigiCert reported remediation progress and provided a count of certificates issued using the improper domain validation method.
- DigiCert reported completion of revalidation and remediation, including that no certificates were revoked.
- DigiCert — Opened the disclosure describing the investigation trigger, the validation process issue, the August 13 issuance stop, and that impacted certificates were under review.
- DigiCert — Updated that 1,233 certificates were issued using the improper domain validation method and that remediation would involve verifying control with the applicant or revoking.
- Community commenter — Asked for clarification on what triggered the investigation, the investigation start time, and details of the controls and manual review.
- DigiCert — Explained the legacy Symantec validation workflow and described how the issue occurred, including that the random-value email could go to an inappropriate address.
- Adacom representative — Questioned whether DigiCert’s certificate list included certificates issued on or after August 13, 2018 and asked if any slipped past the cutoff date.
- DigiCert — Responded that issuance was stopped for additional validations, existing validations were not invalidated until reviewed, and that the listed certificates completed validation before the cutoff but did not issue.
- Fastly representative — Requested periodic remediation updates and a target completion date, and asked what additional actions DigiCert decided to take.
- DigiCert — Said remediation work was ongoing and that an update would be posted the next week, including improvements for detection and prevention.
- DigiCert — Reported that everything was revalidated and approved using a BR-compliant method, that zero certificates were revoked, and described prevention/detection improvements including reducing manual steps and using machine learning for document detection.