DigiCert: Verizon: Certificates issued with incorrect subject localityName (“Default City”)
The bug reports that a batch of Verizon/DigiCert certificates contained an incorrect subject:localityName value of “Default City.” The issue was identified after a list of affected certificates was published at https://misissued.com/batch/51/, and Mozilla requested an incident report. DigiCert/Verizon stated that the problem was not automatically checked by their system and required checking by the RA administrator, and that no new certificates were being issued from the affected sub CA (the last certificates were created in March 2018). DigiCert/Verizon revoked the initially reported certificates and confirmed revocation via OCSP, with CRL update expected within 3 hours. They then reviewed additional certificates and identified 83 additional certificates with the same problem, stating they would revoke them within the 5-day window. DigiCert later confirmed that the certificates were revoked (with crt.sh links provided) and that remediation was complete.
- A list of Verizon/DigiCert certificates with subject localityName set to “Default City” was published, prompting an incident report request.
- The initially identified certificates were revoked and CRL creation was performed.
- DigiCert/Verizon confirmed revocation of the remaining identified certificates and remediation completion.
- Fastly representative — Requested an incident report after noting Verizon/DigiCert certificates had subject:localityName set to “Default City,” citing BR section 7.1.4.2.2(e) and linking to https://misissued.com/batch/51/.
- DigiCert — Updated that the Verizon certificates were revoked and confirmed via OCSP, and stated work would continue on filing the incident report.
- DigiCert — Noted the certificates were issued by Verizon through their Sub CA, which had shut down issuance, and that new certificates would go through DigiCert systems.
- DigiCert — Provided incident report details including when DigiCert became aware, a timeline, counts of problematic certificates, and stated that 83 additional certificates would be revoked within the 5-day window.
- Fastly representative — Asked Brenda to confirm when all certificates had been revoked.
- DigiCert — Confirmed the certificates were revoked as of that Saturday and provided crt.sh links for revoked certificates.
- Fastly representative — Commented that it appears remediation is complete.