← DigiCert cases
Bugzilla #1500621 Certificate Misissuance Self Reported Incident

DigiCert: Internal domain name certificate misissuance

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On 10/16/2018, DigiCert was notified by a third party that an internal name appeared on a publicly issued certificate within the past week. DigiCert investigated and identified a gap in its domain pre-validation process that allowed a certificate containing an internal name to be submitted for validation by a customer. DigiCert stated that a validation agent overrode the base domain’s classification as “private” and manually performed a WHOIS procedure, which enabled the agent to send a domain confirmation email and the customer to approve the internal name in response to the method 2 confirmation. DigiCert also explained that the override was intended to be used when automated WHOIS data retrieval failed, but it unintentionally allowed incorrect approval for WebPKI issuance. On 10/17/2018, DigiCert revoked the one problem certificate and moved the pre-issuance check behind the validation process so internal names are blocked for public certs regardless of validation staff mistakes. DigiCert also implemented portal changes to prevent the gap that allowed internal names into domain pre-validation for WebPKI and improved pre-issuance linting; it ran a script over its existing certificate database and reported no additional affected certificates. The bug was marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 11:24 UTC Revised: 2026-06-16 18:55 UTC Confidence: 0.90 3 comments
Chronology
  1. DigiCert was notified by a third party about a publicly issued certificate containing an internal name.
  2. DigiCert revoked the problem certificate and implemented fixes to block internal names for public issuance.
Thread Activity
  1. DigiCert — Brenda Bernal described how DigiCert became aware of the issue, the root cause in domain pre-validation/WHOIS override behavior, and the corrective actions taken (revocation, process change, portal changes, and linting improvements).
  2. Fastly representative — Wyane Thayer asked DigiCert to post the report to mozilla.dev.security.policy and requested an explanation of how pre-issuance linting missed the issue.
  3. DigiCert — Jeremy Rowley explained that DigiCert used a modified cablint that warned but did not block, replaced it with zlint, planned to hard-fail it, and provided a detailed account of how the linter warning was bypassed and DCV proceeded.
Participants
DigiCert Fastly representative
External References
Similar Local Cases
#1515788 RESOLVED Self Reported Incident Opened 2018-12-20 · Closed 2023-02-22 · 100% similar
DigiCert: Underscores - CVS Pharmacy
#1516545 RESOLVED Self Reported Incident Opened 2018-12-27 · Closed 2023-02-22 · 100% similar
DigiCert: Underscores - Verizon
#1548716 RESOLVED Self Reported Incident Opened 2019-05-02 · Closed 2023-02-22 · 100% similar
DigiCert: Verizon: "Default City" in Subject:localityName
#1650910 RESOLVED Self Reported Incident Audit Finding Revocation Issue Opened 2020-07-06 · Closed 2023-02-22 · 100% similar
DigiCert: Inconsistent EV audits
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 97% similar
DigiCert: Issuance of Cert with Compromised Key
#1894560 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-05-01 · Closed 2024-07-03 · 97% similar
DigiCert: Incorrect case in Business Category
#1401407 RESOLVED Self Reported Incident Opened 2017-09-19 · Closed 2023-02-22 · 96% similar
DigiCert: Mis-Issuance Rekey certificates
#1483715 RESOLVED Self Reported Incident Opened 2018-08-15 · Closed 2024-06-30 · 95% similar
DigiCert: improper use of domain validation method

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action