← DigiCert cases
Bugzilla #1618256
Certificate Problem Report
DigiCert: Failure to properly encode Subject name
RESOLVED
DigiCert
AI Summary
DigiCert identified a failure to properly encode subject names in certain certificates, leading to non-compliance with the Baseline Requirements. Following an internal audit, DigiCert revoked 33 affected certificates and reported the incident to Mozilla. The issue stemmed from a previous compliance patch that did not retroactively address existing certificates. DigiCert has since implemented comprehensive scanning and compliance measures to prevent future occurrences.
Chronology
- Compliance analytics team ran linter analysis on existing active certificates
- List of 33 active certificates revoked
- Bug 1618256 opened to file a separate incident report
Participants
Ryan Sleevi
Brenda Bernal
External References
Similar Local Cases
DigiCert: CAA Checking Issue
DigiCert: Incorrect RegNumber-Org Type combination
DigiCert: Invalid localityName
DigiCert: Failure to provide a preliminary report within 24 hours.
DigiCert: "Internet Widgits Pty Ltd" in organizationalUnitName
DigiCert: OCSP NextUpdate
DigiCert: Underscores - Citi
DigiCert: Failure to revoke within 7 days: OCSP EKU issue