← Sectigo cases
Bugzilla #1645686 Certificate Problem Report

Sectigo: Lack of input validation in stateOrProvinceName

RESOLVED DUPLICATE Sectigo
AI Summary

This case addresses a significant issue with Sectigo's input validation for the stateOrProvinceName field in their EV certificates. Multiple misissued certificates were identified, including incorrect values such as 'Default Province' and 'null'. The problem was acknowledged by Sectigo, which indicated that the certificates were queued for revocation. The case highlights the challenges in ensuring compliance with validation requirements and the need for improved oversight in certificate issuance processes.

Model: gpt-4o-mini Generated: 2026-06-13 20:58 UTC Confidence: 0.95
Chronology
  1. Initial report of misissued certificates due to lack of input validation.
  2. Sectigo acknowledges the issue and begins investigation.
  3. Sectigo implements changes to prevent future misissuance.
  4. All certificates with invalid ST fields were revoked or expired.
Participants
Rich Smith George [:fozzie] Ryan Sleevi Robin Alden Paul Leo Steinberg Ben Wilson Tim Callan
Similar Local Cases
#1648717 RESOLVED Certificate Problem Report Opened 2020-06-26 · Closed 2023-02-22 · 77% similar
Sectigo: Failure to provide a preliminary report within 24 hours.
#1575022 RESOLVED Certificate Problem Report Opened 2019-08-19 · Closed 2023-02-22 · 75% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1639805 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 74% similar
Sectigo: Failure to revoke key-compromised certificates
#1715024 RESOLVED Certificate Problem Report Opened 2021-06-07 · Closed 2023-02-22 · 74% similar
Sectigo: Misspellings in stateOrProvince or localityName fields
#1724458 RESOLVED Certificate Problem Report Opened 2021-08-06 · Closed 2023-02-22 · 74% similar
Sectigo: Mojibake in certificate Subject fields
#1741777 RESOLVED Certificate Problem Report Opened 2021-11-18 · Closed 2023-02-22 · 73% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1563579 RESOLVED Certificate Problem Report Opened 2019-07-04 · Closed 2023-02-22 · 73% similar
Sectigo: Failure to provide timely incident reports
#1650845 RESOLVED Certificate Problem Report Opened 2020-07-06 · Closed 2024-06-30 · 72% similar
Sectigo: CPR response issues

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action