← Sectigo cases
Bugzilla #1694233
Validation Issue
Sectigo: Inadequate DCV
RESOLVED
FIXED
Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Sectigo reported an incident regarding inadequate Domain Control Validation (DCV) that allowed the issuance of SSL certificates without proper validation for apex domains. The issue was identified following a report from a partner on February 10, 2021. Sectigo investigated and confirmed the flaw, leading to a code fix deployed on February 11, 2021. Affected certificates were identified, and notifications were sent to subscribers, resulting in the revocation of 1,548 certificates by February 19, 2021. The CA has since implemented measures to prevent similar issues in the future.
Chronology
- Sectigo received a report indicating inadequate DCV for apex domains.
- Code fix deployed to prevent issuance of certificates without proper DCV.
- Revocation of 1,548 affected certificates completed.
Thread Activity
- Sectigo — Sectigo created a detailed report outlining the incident and actions taken.
- Community commenter — Inquired about the differences between this incident and a previous one involving Sectigo.
- Sectigo — Explained the differences in scope and nature between the current and previous incidents.
- Sectigo — Provided updates on ongoing discussions and actions regarding the incident.
Participants
Sectigo
Community commenter
External References
Similar Local Cases
FNMT: Issuance of QCP-n certificates without verifying identity
Google Trust Services: Failure to properly validate IP address
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate
Multicert: AIA CA Issuer field pointing to PEM encoded cert
GlobalSign: SSL Certificates with US country code and invalid State/Prov
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions
eMudhra emSign PKI Services : OCSP Responder Time Inconsistency