Sectigo: invalid subject:organizationalUnitName on DV certificates
Sectigo faced issues with the inclusion of invalid organizational unit (OU) names in domain validation (DV) certificates. The OU fields were populated with branding and product names, which did not comply with the Baseline Requirements. Following the identification of this problem, Sectigo acknowledged the issue and committed to ceasing the practice of including such OU fields. The resolution involved a code change to their certificate issuance system, which was implemented by December 15, 2019. The case highlights the importance of adhering to certificate issuance standards to maintain trust in the certificate ecosystem.
- Sectigo became aware of the problem via a mailing list post.
- Bug reported by Matthias.
- Sectigo ceased issuing DV certificates with problematic OU fields.