← DigiCert cases
Bugzilla #1684442
Certificate Misissuance
DigiCert: SHA-1 intermediate issued after 2016-01-01
RESOLVED
DigiCert
AI Summary
DigiCert issued a SHA-1 intermediate certificate after the January 1, 2016 deadline, which violates Mozilla's policy. The certificate, intended for timestamping, was created on December 17, 2020, and was found to be non-compliant during a routine compliance review on December 28, 2020. DigiCert promptly revoked the certificate and has since implemented measures to prevent future occurrences, including a hard-block on SHA-1 intermediate certificates.
Chronology
- Intermediate certificate created
- Compliance issue identified and certificate revoked
Participants
Rob Stradling
Jeremy Rowley
Brenda Bernal
External References
Similar Local Cases
DigiCert: "Some-State" in stateOrProvinceName
DigiCert: Internal Domain Name cert mis-issuance
DigiCert: Underscores - CVS Pharmacy
DigiCert: DigiCert issued cert with CN too long
DigiCert: Verizon mis-issued test certificates
Digicert: Failure to include CPS URI in 1 certificate
DigiCert: in-addr.arpa Misissuance
DigiCert / ABB: greater than 825 day cert issuance