← DigiCert cases
Bugzilla #1654967
Self Reported Incident
Revocation Issue
DigiCert: Malformed ICA
RESOLVED
FIXED
DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
DigiCert identified a compliance issue during a post-issuance review of a key ceremony, where an issuing CA was created without the required CRL extension. This discovery led to a scan revealing nine additional ICAs with similar errors. DigiCert has ceased issuing new certificates until the key ceremony process is fully automated to prevent human error. They have outlined a timeline of actions taken in response to the incident, including revocations and plans for improved automation in their processes.
Chronology
- DigiCert discovered a compliance failure during a key ceremony review.
- DigiCert scheduled additional ICAs for revocation.
- DigiCert began implementing automation in their key ceremony process.
- DigiCert completed a public key ceremony using the new automated tool.
Thread Activity
- Community commenter — DigiCert reported a compliance failure discovered during a key ceremony.
- DigiCert — Additional checks for the ICA process were discussed.
- DigiCert — Root causes of the incident were identified and discussed.
- Community commenter — DigiCert confirmed the successful completion of a public key ceremony.
Participants
Community commenter
DigiCert
Sectigo
Mozilla representative
External References
Similar Local Cases
DigiCert: Underscores - CVS Pharmacy
DigiCert: Underscores - Verizon
DigiCert: Issuance of Cert with Compromised Key
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
DigiCert: Failure to provide a preliminary report within 24 hours.
DigiCert: Incorrect OCSP Delegated Responder Certificate
DigiCert: Inconsistent EV audits
DigiCert: Incorrect RegNumber-Org Type combination