← Sectigo cases
Bugzilla #1593776 Ca Certificate Compliance Incident

Sectigo: invalid subject:organizationalUnitName on DV certificates

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Sectigo's discovery of a compliance issue regarding the use of the organizationalUnitName (OU) field in Domain Validated (DV) certificates. Sectigo acknowledged that many DV certificates included OU fields with values that did not correspond to validated subject information, which is a violation of the Baseline Requirements. In response, Sectigo committed to ceasing the practice of including such values and implemented changes to their certificate issuance process by December 15, 2019. The issue was resolved with the implementation of these changes, and Sectigo has since stopped issuing DV certificates with problematic OU fields.

Model: gpt-4o-mini Generated: 2026-06-13 20:17 UTC Revised: 2026-06-16 18:40 UTC Confidence: 0.90 22 comments
Chronology
  1. Sectigo became aware of the issue through a discussion in the Mozilla security policy mailing list.
  2. Sectigo implemented changes to stop including non-validated OU fields in DV certificates.
Thread Activity
  1. Thisisntrocket representative — Opened the bug reporting the issue with OU fields in Sectigo's DV certificates.
  2. Sectigo — Acknowledged the report and outlined Sectigo's understanding of the relevant Baseline Requirements.
  3. Sectigo — Confirmed that Sectigo had implemented the planned changes to remove additional OU fields.
  4. Mozilla representative — Indicated that the bug could be closed as Sectigo had ceased issuing problematic certificates.
Participants
Thisisntrocket representative Sectigo Community commenter Mozilla representative
External References
Similar Local Cases
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 100% similar
Sectigo: Incorrect OCSP responses
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 100% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1597950 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-20 · Closed 2023-02-22 · 100% similar
Sectigo: CCADB failed ALV - Ensured Root CA
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 100% similar
Sectigo: CPR response issues
#1518553 RESOLVED Ca Certificate Compliance Opened 2019-01-08 · Closed 2023-02-22 · 97% similar
Sectigo: Use of forbidden subjectPublicKeyInfo algorithm
#1720744 RESOLVED Ca Certificate Compliance Opened 2021-07-15 · Closed 2023-02-22 · 97% similar
Sectigo: State name in localityName
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 95% similar
Sectigo: Failure to block disallowed LDH labels in domain names

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action