← Sectigo cases
Bugzilla #1575022 Ca Certificate Compliance Certificate Misissuance Self Reported Incident

Sectigo: EV SSL Certificates with incorrect subject details.

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a compliance issue involving EV SSL certificates that contained incorrect subject details, specifically related to the Jurisdiction of Incorporation (JoI) and subject:serialNumber fields. The CA became aware of the problem through multiple user reports received between August 16 and August 27, 2019. In response, Sectigo initiated the revocation of affected certificates and implemented a series of corrective actions, including deploying code to prevent the issuance of certificates with invalid data. The issue was resolved with the implementation of a JoI policy checker and other validation improvements, and the bug was marked as fixed on February 22, 2023.

Model: gpt-4o-mini Generated: 2026-06-13 19:33 UTC Revised: 2026-06-16 18:38 UTC Confidence: 0.85 29 comments
Chronology
  1. First problem report received regarding incorrect subject details.
  2. Sectigo committed to providing regular updates on the incident.
  3. Bug marked as resolved after corrective actions were implemented.
Thread Activity
  1. Sectigo — Sectigo acknowledged the issue and began revoking affected certificates.
  2. Fastly representative — Requested a remediation timeline from Sectigo.
  3. Sectigo — Published a list of identified certificates with JoI mismatches.
  4. Sectigo — Bug marked as fixed after implementing necessary changes.
Participants
Sectigo Fastly representative DigiCert Community commenter Mozilla representative
External References
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 100% similar
Sectigo: Incorrect JOI for federal credit unions
#1518553 RESOLVED Ca Certificate Compliance Opened 2019-01-08 · Closed 2023-02-22 · 100% similar
Sectigo: Use of forbidden subjectPublicKeyInfo algorithm
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1593776 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-04 · Closed 2023-02-22 · 100% similar
Sectigo: invalid subject:organizationalUnitName on DV certificates
#1620561 RESOLVED Self Reported Incident Opened 2020-03-06 · Closed 2023-02-22 · 100% similar
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 100% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 100% similar
Sectigo: CPR response issues

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action