← Sectigo cases
Bugzilla #1551362
Certificate Problem Report
Sectigo: "Some-State" in stateOrProvinceName
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo was reported for issuing certificates containing the placeholder 'Some-State' in the stateOrProvinceName field, which was not validated according to the Baseline Requirements. The issue was identified after a report was made on May 11, 2019, leading to the revocation of 78 certificates. Although most were revoked promptly, three certificates remained unrevoked for a period due to administrative errors. Sectigo has since implemented measures to prevent similar issues in the future, including a new incident response playbook and a tracking system for revocations.
Chronology
- Initial report received regarding misissued certificates.
- Revocation process started for identified certificates.
- All identified certificates were revoked.
Participants
Wayne Thayer
Robin Alden
Ryan Sleevi
Alex Cohn
External References
Similar Local Cases
Sectigo: EV SSL Certificates with incorrect subject details.
Sectigo: "Default City" in Subject:localityName
Sectigo: Failure to provide a preliminary report within 24 hours.
Sectigo: Failure to revoke within 24 hours
Sectigo: invalid dnsName
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates
Sectigo: Failure to provide a preliminary report within 24 hours
Sectigo: Failure to revoke key-compromised certificates