← DigiCert cases
Bugzilla #1675923 Ca Certificate Compliance Certificate Misissuance

DigiCert: TERENA: Insufficient validation of organizationalUnitName

RESOLVED INVALID DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Michel Le Bihan reported two DigiCert-issued certificates associated with TERENA that he said had expired and involved `organizationalUnitName` values containing `Informatyzacja Uczelni` with specific CNs. He noted that one certificate was revoked a day after issuance and asked whether this could be a misissuance issue, but said he was reporting it “just in case.” Mozilla staff responded that the certificates expired in early 2019 and questioned whether they might have been reported previously, stating they were not sure anything actionable remained. George Fozzie Dev said that even if there were a violation, DigiCert had implemented constraints for this field in another bug (1639032). Jeremy Rowley from DigiCert replied that the certificates had been expired for almost two years, that DigiCert had turned off OU in general with some exception accounts, and that DigiCert had implemented additional checking and redid its validation system referenced in bug 1639032. The bug was resolved as INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 11:39 UTC Revised: 2026-06-16 19:05 UTC Confidence: 0.86 4 comments
Chronology
  1. Michel Le Bihan reported two DigiCert-issued certificates with `organizationalUnitName` values that he said were insufficiently validated and later expired/revoked.
  2. Mozilla staff and other participants discussed whether the certificates were already known and whether there was any actionable remediation given their age.
  3. DigiCert stated it had implemented constraints and validation changes for this field and had turned off OU generally with exceptions.
Thread Activity
  1. Lebihan representative — Reported two certificates (crt.sh links) that he said expired and involved specific `organizationalUnitName` values, and asked if it could be misissuance.
  2. Mozilla representative — Asked how to know the certificates weren’t already reported and said they were not sure anything actionable remained.
  3. Fozzie representative — Said that even if it were a violation, DigiCert had implemented constraints for this field in bug 1639032.
  4. DigiCert — Stated the certificates had been expired for almost two years, OU was turned off generally with exceptions, and DigiCert redid validation and checking referenced in bug 1639032 and a related URL.
Participants
Lebihan representative Mozilla representative Fozzie representative DigiCert
Related Bugzilla IDs Mentioned
Similar Local Cases
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 100% similar
DigiCert: Invalid localityName
#1759122 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-11 · Closed 2022-11-14 · 100% similar
DigiCert: EV for Onion addresses without Tor Service Descriptor
#1586604 RESOLVED Certificate Misissuance Validation Issue Opened 2019-10-06 · Closed 2022-11-14 · 96% similar
DigiCert: TERENA: No localityName in EV precert
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 90% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities
#1518555 RESOLVED Certificate Misissuance Opened 2019-01-08 · Closed 2023-02-22 · 88% similar
DigiCert: Use of forbidden subjectPublicKeyInfo algorithm
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 88% similar
DigiCert: Misissuance detected by PKIMetal
#1262610 RESOLVED Ca Certificate Compliance Opened 2016-04-06 · Closed 2023-02-22 · 87% similar
DigiCert: ECCE 001 issuing certificates without subject alternative name extension
#1664325 RESOLVED Ca Certificate Compliance Opened 2020-09-10 · Closed 2023-02-22 · 86% similar
DigiCert: SHA-256 hash algorithm used with ECC P-384 key

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action