← DigiCert cases
Bugzilla #1483715 Self Reported Incident

DigiCert: improper use of domain validation method

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert reported that, after a customer requested information about the validation process for four domains, DigiCert investigated and found that the domains were not properly validated using a post-Aug 1 domain validation method. DigiCert said that when attempting to revalidate the domains prior to August 1, the random value was sent to an address other than the WHOIS contact, which led to a broader investigation into its revalidation efforts. DigiCert stated that from February through April 2018 it permitted some legacy Symantec customers to use Method 1, and that around April the process was modified to include a BR-compliant Random Value, effectively transforming the validation from Method 1 to Method 2. DigiCert reported that on August 13, 2018 it stopped all issuance based on the process that converted Method 1 validations to Method 2 validations, and that impacted certificates were under review (initially described as just under 2,500). In a later update, DigiCert stated that there were 1,233 certificates issued using the improper domain validation method and that remediation was underway via verifying control with the applicant or revoking. DigiCert ultimately reported that everything was revalidated and approved using a BR-compliant method and that, as suspected, exactly zero certificates were revoked; it also described plans to improve detection and prevention by reducing manual steps and restricting validation staff input, and by using machine learning to detect WHOIS-like documents.

Model: gpt-5.4-nano Generated: 2026-06-13 11:23 UTC Revised: 2026-06-16 18:54 UTC Confidence: 0.90 9 comments
Chronology
  1. A customer requested information about DigiCert’s validation process for four domains, prompting DigiCert’s investigation.
  2. DigiCert stopped issuance based on the process converting legacy Method 1 validations to Method 2 validations.
  3. DigiCert reported remediation progress and provided a count of certificates issued using the improper domain validation method.
  4. DigiCert reported completion of revalidation and remediation, including that no certificates were revoked.
Thread Activity
  1. DigiCert — Opened the disclosure describing the investigation trigger, the validation process issue, the August 13 issuance stop, and that impacted certificates were under review.
  2. DigiCert — Updated that 1,233 certificates were issued using the improper domain validation method and that remediation would involve verifying control with the applicant or revoking.
  3. Community commenter — Asked for clarification on what triggered the investigation, the investigation start time, and details of the controls and manual review.
  4. DigiCert — Explained the legacy Symantec validation workflow and described how the issue occurred, including that the random-value email could go to an inappropriate address.
  5. Adacom representative — Questioned whether DigiCert’s certificate list included certificates issued on or after August 13, 2018 and asked if any slipped past the cutoff date.
  6. DigiCert — Responded that issuance was stopped for additional validations, existing validations were not invalidated until reviewed, and that the listed certificates completed validation before the cutoff but did not issue.
  7. Fastly representative — Requested periodic remediation updates and a target completion date, and asked what additional actions DigiCert decided to take.
  8. DigiCert — Said remediation work was ongoing and that an update would be posted the next week, including improvements for detection and prevention.
  9. DigiCert — Reported that everything was revalidated and approved using a BR-compliant method, that zero certificates were revoked, and described prevention/detection improvements including reducing manual steps and using machine learning for document detection.
Participants
DigiCert Community commenter Adacom representative Fastly representative
Similar Local Cases
#1515788 RESOLVED Self Reported Incident Opened 2018-12-20 · Closed 2023-02-22 · 100% similar
DigiCert: Underscores - CVS Pharmacy
#1516545 RESOLVED Self Reported Incident Opened 2018-12-27 · Closed 2023-02-22 · 100% similar
DigiCert: Underscores - Verizon
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 100% similar
DigiCert: Issuance of Cert with Compromised Key
#1650910 RESOLVED Self Reported Incident Audit Finding Revocation Issue Opened 2020-07-06 · Closed 2023-02-22 · 100% similar
DigiCert: Inconsistent EV audits
#1397969 RESOLVED Self Reported Incident Opened 2017-09-08 · Closed 2023-02-22 · 100% similar
DigiCert / Inteso San Paulo: Double dot characters
#1401407 RESOLVED Self Reported Incident Opened 2017-09-19 · Closed 2023-02-22 · 100% similar
DigiCert: Mis-Issuance Rekey certificates
#1500621 RESOLVED Certificate Misissuance Self Reported Incident Opened 2018-10-19 · Closed 2023-02-22 · 95% similar
DigiCert: Internal Domain Name cert mis-issuance
#1548716 RESOLVED Self Reported Incident Opened 2019-05-02 · Closed 2023-02-22 · 95% similar
DigiCert: Verizon: "Default City" in Subject:localityName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action