Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
This case involves Dhimyotis/Certigna, which issued certificates with validity periods exceeding the 398-day limit mandated by the Baseline Requirements. The issue was identified internally, and the CA acknowledged a configuration error that resulted in the issuance of certificates with a duration of 398 days and 1 second. Following the discovery, Certigna promptly updated its certificate generation service to prevent future occurrences and initiated the revocation of the affected certificates. By October 26, 2020, all non-compliant certificates had been revoked, and the CA committed to improving its practices to ensure compliance with the validity period requirements.
- Dhimyotis/Certigna identified and acknowledged the issuance of non-compliant certificates.
- All affected certificates were revoked.
- Sectigo — Reported that Certigna issued certificates with validity periods greater than 398 days.
- Dhimyotis representative — Acknowledged the issue and promised a consolidated response.
- Certigna — Confirmed the issuance of non-compliant certificates due to a configuration error.
- Dhimyotis representative — Confirmed initiation of the revocation process for the affected certificates.
- Dhimyotis representative — Informed that all affected certificates have been revoked.