DigiCert: Domain validation skipped
DigiCert reported a compliance issue where domain validation was skipped during the issuance of certificates due to a patch applied to their API. This incident was discovered during an escape analysis following a SEV1 outage. The CA identified that the patch allowed the legacy issuer code to bypass the domain validation system, resulting in the mis-issuance of 123 OV and 36 EV certificates. DigiCert took immediate action by revoking all impacted certificates within 24 hours of identifying the issue and is implementing a new architecture to prevent future occurrences. The CA is also enhancing their testing and monitoring processes to ensure compliance.
- A SEV1 outage was reported for a storefront.
- All impacted certificates were revoked within 24 hours of knowing which certificates were impacted.
- DigiCert — DigiCert discovered the issue during an escape analysis after a SEV1 store-front fix.
- Community commenter — Requested more complete data to identify affected certificates.
- DigiCert — Explained how the patch allowed the legacy issuer code to bypass domain validation.
- Fastly representative — Agreed to resolve the bug due to comprehensive remediation steps provided by DigiCert.