← DigiCert cases
Bugzilla #1526154
Certificate Problem Report
DigiCert: Missed Underscore Certificate Revocations
RESOLVED
DigiCert
AI Summary
DigiCert identified a failure to revoke 17 valid certificates containing underscores, which were not included in their incident reports. The issue arose from a flaw in their data extraction script, which led to missed revocations. DigiCert has since ceased issuing underscore certificates and is actively revoking the problematic certificates. They have implemented measures to enhance their data reporting processes to prevent future occurrences.
Chronology
- Third party reported unrevoked underscore certificates.
- DigiCert revoked remaining valid underscore certificates.
- DigiCert began revoking pre-certificates without valid certificates.
- DigiCert ceased issuance of underscore certificates.
Participants
Brenda Bernal
Wayne Thayer
External References
Similar Local Cases
DigiCert: Undisclosed CAs -Federated Trust CA-1
DigiCert: Invalid Country Code Issuance
DigiCert: P-384,ecdsa-with-SHA512 Certificates
DigiCert / ABB: Issues with DN, country code and keyUsage
DigiCert: Symantec non-constrained/non-disclosed intermediate CA certificates
DigiCert: OCSP not responding issue
DigiCert: Failure to properly encode Subject name
DigiCert: BR 3.2.5 Validation of Authority Failure for OV Certs