← Sectigo cases
Bugzilla #1518553
Certificate Problem Report
Sectigo: Use of forbidden subjectPublicKeyInfo algorithm
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo faced issues with the issuance of certificates containing the forbidden P-521 public key algorithm. The problem was identified through discussions in the Mozilla security policy forum. Sectigo responded by implementing a code change to prevent further issuance of such certificates. However, it was later revealed that the code change only addressed one of two pathways for certificate issuance, allowing some certificates with P-521 keys to be issued. Sectigo has since taken steps to ensure compliance with Mozilla's policies and has committed to improving their QA processes.
Chronology
- Initial report of P-521 key usage
- Code change implemented to stop issuing P-521 certificates
- Further code change implemented to close off remaining issuance pathway
Participants
Ryan Sleevi
Robin Alden
External References
Similar Local Cases
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates
Sectigo: Failure to provide a preliminary report within 24 hours
Sectigo: invalid subject:organizationalUnitName on DV certificates
Sectigo: EV SSL Certificates with incorrect businessCategory
Sectigo: EV SSL Certificates with incorrect subject details.
Sectigo: "Default City" in Subject:localityName
Sectigo: Failure to provide timely incident reports
Sectigo: "Some-State" in stateOrProvinceName