← Sectigo cases
Bugzilla #1620561 Self Reported Incident

Sectigo non-revocation of DV certificates containing subject:organizationalUnitName

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo opened this bug to disclose that it had issued a large number of DV SSL certificates containing subject:organizationalUnitName and had decided not to revoke them immediately. Sectigo said it believed the BR language in section 7.1.4.2.2(i) was unclear or misdrafted, and initially planned to let the certificates expire naturally while it worked on a CA/B Forum ballot to clarify the wording. Mozilla and other commenters pushed back, asking for a clearer revocation plan and more concrete remediation. Sectigo later said it would revisit the report, provided counts of affected certificates, and described bulk revocations and natural expiry over time. By November 2020, Sectigo reported 737,637 revocations for certs under wd2go.com and said it was working with Western Digital to migrate to 90-day certificate duration. The bug was later marked RESOLVED with FIXED, and Mozilla indicated it was inclined to close the matter after adequate discussion.

Model: gpt-5.4-mini Generated: 2026-06-13 20:58 UTC Revised: 2026-06-16 18:43 UTC Confidence: 0.96 35 comments
Chronology
  1. Sectigo disclosed DV certificates issued with subject:organizationalUnitName and said it would not immediately revoke them.
  2. Sectigo reported millions of affected certificates, with many already expired and some already replaced and revoked.
  3. Sectigo said about 4.8 million valid certificates remained and that around 700,000 might be revocable for one partner.
  4. Sectigo processed 737,637 revocations for certificates issued under wd2go.com and said it was working to move to 90-day certificates.
  5. Mozilla said it was inclined to close the matter as having had adequate discussion.
Thread Activity
  1. Sectigo — Sectigo said it had stopped including OU fields in DV certificates and opened the bug because it would not revoke the affected certificates immediately.
  2. Community commenter — Ryan said Sectigo’s response lacked data and asked it to revisit the report and explain how it would prevent future delays.
  3. Sectigo — Sectigo said it would revisit the report and provide more analysis on the affected certificates.
  4. Sectigo — Sectigo reported expiry, replacement, and revocation counts, and said some certificates were on consumer devices that could not be updated before expiry.
  5. Sectigo — Sectigo said it would propose a CA/B Forum ballot to restate 7.1.4.2.2(i) more clearly.
  6. Sectigo — Sectigo said it would provide an update after a meeting with a subscriber holding most of the affected certificates.
  7. Sectigo — Sectigo said about 4.8 million valid certificates remained, most with one partner, and that revocation was limited by device impact.
  8. Sectigo — Sectigo said the devices had no remote software update mechanism and that revocation would require manual firmware update or factory reset.
  9. Sectigo — Sectigo said it had processed 737,637 revocations for wd2go.com and was working with Western Digital on 90-day certificate duration.
  10. Mozilla representative — Mozilla said it was inclined to close the matter as having had adequate discussion.
Participants
Sectigo Community commenter Thisisntrocket representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 100% similar
Sectigo: Incorrect JOI for federal credit unions
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 100% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 100% similar
Sectigo: CPR response issues
#1699756 RESOLVED Self Reported Incident Opened 2021-03-19 · Closed 2022-11-14 · 100% similar
Sectigo: Reseller ZeroSSL and Private Key Generation
#1715024 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-06-07 · Closed 2023-02-22 · 100% similar
Sectigo: Misspellings in stateOrProvince or localityName fields
#1718771 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2023-02-22 · 100% similar
Sectigo: DCV Reuse after 825 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action