← Sectigo cases
Bugzilla #1524730 Certificate Misissuance Revocation Issue

Sectigo: invalid dnsName

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns a certificate issued by a Sectigo sub-CA that contained an invalid dnsName value (`DNS=advisors.intel.com`). The issue was reported to Sectigo via its abuse reporting email address on 25-JAN-19, referencing a crt.sh/zlint entry for the certificate. Sectigo passed the report to the operator of the Name-constrained sub-CA that issued the end-entity certificate, and the operator reported that the certificate had been revoked the same day. Sectigo stated it stopped issuing certificates with the problem and that the Name-constrained sub-CA that issued the certificates had ceased issuing. Sectigo provided details that four certificates with the problem were detected, with issuance dates ranging from 11-JUL-16 to 19-May-17, and that three had been previously revoked for other reasons and later expired. Sectigo attributed the mistake to human error at the sub-CA operator (pasting a literal value including the `DNS=` prefix) and to a systems failing that allowed the incorrect value to be signed. As remediation, Sectigo said it introduced a policy requiring automated lint checking of tbsCertificates before signing, and it later confirmed that it lint-checked other currently valid certificates issued by the same sub-CA with no lint errors. The thread indicates the questions were answered and remediation was complete, and the bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 18:00 UTC Revised: 2026-06-16 18:33 UTC Confidence: 0.86 7 comments
Chronology
  1. A certificate with the invalid dnsName issue was issued by the Name-constrained sub-CA.
  2. The last certificate with the invalid dnsName issue was issued by the Name-constrained sub-CA.
  3. Sectigo received a report about a certificate with an invalid dnsName and the issuing sub-CA operator reported revocation the same day.
  4. Sectigo provided additional responses, including confirmation that other currently valid certificates were lint-checked.
  5. A reviewer stated it appeared all questions were answered and remediation was complete.
Thread Activity
  1. Titanous representative — Reported that a Sectigo sub-CA issued a certificate with an invalid dnsName (`DNS=advisors.intel.com`), linked to crt.sh/zlint, and stated the certificate was revoked the same day after reporting.
  2. Fastly representative — Asked Robin to provide an incident report per Mozilla guidance.
  3. Sectigo — Submitted a detailed incident response including how Sectigo became aware, a timeline of actions, confirmation that issuing stopped, certificate details, root cause, and remediation steps (automated lint checking before signing).
  4. Titanous representative — Asked whether Sectigo linted currently valid certificates issued by the sub-CA for other invalid dnsNames.
  5. Sectigo — Confirmed that Sectigo lint-checked all other currently valid certificates issued by the sub-CA and found no lint errors.
  6. Fastly representative — Stated it appeared all questions had been answered and remediation was complete.
Participants
Titanous representative Fastly representative Sectigo Community commenter
Similar Local Cases
#1590810 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-23 · Closed 2023-02-22 · 100% similar
Sectigo: EV SSL Certificates with incorrect businessCategory
#1902748 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-06-14 · Closed 2026-06-10 · 89% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 88% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8
#1390977 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 86% similar
Camerfirma: Non-BR-Compliant Certificate Issuance
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 85% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1524876 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 85% similar
Entrust: IP in dnsName
#1536287 RESOLVED Certificate Misissuance Opened 2019-03-18 · Closed 2023-02-22 · 85% similar
Entrust: AffirmTrust Issuing CA Impacted by EJBCA Serial Number Issue
#1390990 RESOLVED Certificate Misissuance Delayed Revocation Opened 2017-08-16 · Closed 2023-02-22 · 85% similar
D-TRUST: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action