← Sectigo cases
Bugzilla #1694233 Certificate Problem Report

Sectigo: Inadequate DCV

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified a flaw in their Domain Control Validation (DCV) process that allowed SSL certificates to be issued without proper validation for apex domains. This issue arose when a subscriber requested a certificate for a www subdomain but did not provide an email address for the apex domain. Following a report from a partner, Sectigo promptly investigated and confirmed the issue, leading to the revocation of 1,548 affected certificates. The company has since implemented code changes to prevent future occurrences of this problem.

Model: gpt-4o-mini Generated: 2026-06-13 20:58 UTC Confidence: 0.90
Chronology
  1. Received report of DCV issue from partner.
  2. Deployed fix to prevent issuance of certificates with incomplete DCV.
  3. Revoked all identified affected certificates.
Participants
Tim Callan Ryan Sleevi Pedro Fuentes
Similar Local Cases
#1648717 RESOLVED Certificate Problem Report Opened 2020-06-26 · Closed 2023-02-22 · 70% similar
Sectigo: Failure to provide a preliminary report within 24 hours.
#1724458 RESOLVED Certificate Problem Report Opened 2021-08-06 · Closed 2023-02-22 · 70% similar
Sectigo: Mojibake in certificate Subject fields
#1715024 RESOLVED Certificate Problem Report Opened 2021-06-07 · Closed 2023-02-22 · 68% similar
Sectigo: Misspellings in stateOrProvince or localityName fields
#1721271 RESOLVED Certificate Problem Report Opened 2021-07-19 · Closed 2023-02-22 · 67% similar
Sectigo: Missing registration numbers in EV certificates
#1740493 RESOLVED Certificate Problem Report Opened 2021-11-10 · Closed 2023-02-22 · 66% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1718771 RESOLVED Certificate Problem Report Opened 2021-06-30 · Closed 2023-02-22 · 66% similar
Sectigo: DCV Reuse after 825 days
#1714193 RESOLVED Certificate Problem Report Opened 2021-06-02 · Closed 2023-02-22 · 65% similar
Sectigo: Incorrect locality information
#1741777 RESOLVED Certificate Problem Report Opened 2021-11-18 · Closed 2023-02-22 · 64% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action