DigiCert: SHA-1 intermediate issued after 2016-01-01
DigiCert discovered that it had issued an intermediate CA certificate, DigiCert Timestamp RSA SHA-1 2020 CA1, using SHA-1 after the Mozilla policy sunset date of January 1, 2016. The issue was identified during a compliance review meeting on December 28, 2020, leading to the conclusion that the certificate was mis-issued. DigiCert promptly revoked the certificate on the same day. The CA has since implemented measures to prevent future occurrences, including a hard-block on issuing SHA-1 intermediates and enhancing its compliance checks. The incident has been resolved with the necessary actions taken.
- DigiCert Timestamp RSA SHA-1 2020 CA1 intermediate created.
- DigiCert identified compliance issue and revoked the certificate.
- Sectigo — Reported the issuance of a SHA-1 intermediate CA certificate.
- DigiCert — Submitted an incident report detailing the compliance violation.
- DigiCert — Provided a follow-up incident report with more detailed analysis.
- Mozilla representative — Scheduled the case for closure as the incident has been addressed.