← Sectigo cases
Bugzilla #1694233 Validation Issue

Sectigo: Inadequate DCV

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported an incident regarding inadequate Domain Control Validation (DCV) that allowed the issuance of SSL certificates without proper validation for apex domains. The issue was identified following a report from a partner on February 10, 2021. Sectigo investigated and confirmed the flaw, leading to a code fix deployed on February 11, 2021. Affected certificates were identified, and notifications were sent to subscribers, resulting in the revocation of 1,548 certificates by February 19, 2021. The CA has since implemented measures to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 20:58 UTC Revised: 2026-06-16 18:48 UTC Confidence: 0.85 26 comments
Chronology
  1. Sectigo received a report indicating inadequate DCV for apex domains.
  2. Code fix deployed to prevent issuance of certificates without proper DCV.
  3. Revocation of 1,548 affected certificates completed.
Thread Activity
  1. Sectigo — Sectigo created a detailed report outlining the incident and actions taken.
  2. Community commenter — Inquired about the differences between this incident and a previous one involving Sectigo.
  3. Sectigo — Explained the differences in scope and nature between the current and previous incidents.
  4. Sectigo — Provided updates on ongoing discussions and actions regarding the incident.
Participants
Sectigo Community commenter
External References
Similar Local Cases
#1693304 RESOLVED Validation Issue Opened 2021-02-17 · Closed 2023-02-22 · 61% similar
FNMT: Issuance of QCP-n certificates without verifying identity
#1876593 RESOLVED Validation Issue Revocation Issue Opened 2024-01-25 · Closed 2024-06-06 · 60% similar
Google Trust Services: Failure to properly validate IP address
#1944815 RESOLVED Self Reported Incident Validation Issue Opened 2025-01-30 · Closed 2026-06-10 · 58% similar
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country
#1666872 RESOLVED Validation Issue Opened 2020-09-23 · Closed 2023-02-22 · 58% similar
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate
#1637093 RESOLVED Validation Issue Opened 2020-05-11 · Closed 2023-02-22 · 58% similar
Multicert: AIA CA Issuer field pointing to PEM encoded cert
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 58% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1576789 RESOLVED Self Reported Incident Validation Issue Opened 2019-08-27 · Closed 2024-05-09 · 57% similar
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions
#1917459 RESOLVED Validation Issue Opened 2024-09-08 · Closed 2025-02-14 · 57% similar
eMudhra emSign PKI Services : OCSP Responder Time Inconsistency

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action