Sectigo: invalid subject:organizationalUnitName on DV certificates
This case involves Sectigo's discovery of a compliance issue regarding the use of the organizationalUnitName (OU) field in Domain Validated (DV) certificates. Sectigo acknowledged that many DV certificates included OU fields with values that did not correspond to validated subject information, which is a violation of the Baseline Requirements. In response, Sectigo committed to ceasing the practice of including such values and implemented changes to their certificate issuance process by December 15, 2019. The issue was resolved with the implementation of these changes, and Sectigo has since stopped issuing DV certificates with problematic OU fields.
- Sectigo became aware of the issue through a discussion in the Mozilla security policy mailing list.
- Sectigo implemented changes to stop including non-validated OU fields in DV certificates.
- Thisisntrocket representative — Opened the bug reporting the issue with OU fields in Sectigo's DV certificates.
- Sectigo — Acknowledged the report and outlined Sectigo's understanding of the relevant Baseline Requirements.
- Sectigo — Confirmed that Sectigo had implemented the planned changes to remove additional OU fields.
- Mozilla representative — Indicated that the bug could be closed as Sectigo had ceased issuing problematic certificates.