← DigiCert cases
Bugzilla #1551363
Certificate Misissuance
DigiCert: "Some-State" in stateOrProvinceName
RESOLVED
DigiCert
AI Summary
DigiCert was reported for issuing certificates with the stateOrProvinceName field set to 'Some-State', a default value from OpenSSL CSRs that indicates a lack of validation. An incident report was requested, leading to a comprehensive review and revocation of affected certificates. DigiCert has since implemented additional validation measures and training to prevent future occurrences.
Chronology
- DigiCert informed of issue with 'Some-State' in certificates.
- All identified problem certificates revoked.
- Final batch of impacted certificates revoked.
- Systematic controls for validation implemented.
Participants
Wayne Thayer
Brenda Bernal
Ryan Sleevi
Jeremy Rowley
External References
Similar Local Cases
DigiCert: Domain validation skipped
DigiCert: Internal Domain Name cert mis-issuance
DigiCert: Underscores - Intuit
DigiCert: Underscores - CVS Pharmacy
DigiCert: SHA-1 intermediate issued after 2016-01-01
DigiCert: in-addr.arpa Misissuance
DigiCert: DigiCert issued cert with CN too long
DigiCert / Telecom Italia: Several Problems