← Certigna cases
Bugzilla #1709896 Certificate Misissuance

Certigna: certificates issued with 2 SCT

RESOLVED INVALID Certigna
AI Summary

Certigna issued 126 SSL certificates with only 2 Signed Certificate Timestamps (SCTs), failing to comply with Apple's requirement for certificates with a lifetime between 181 and 398 days to include 3 SCTs. The issue was identified on May 6, 2021, following a tweet that highlighted the non-compliance. Certigna halted the issuance of SSL certificates upon confirming the problem and is working on replacing the non-compliant certificates. While some participants noted that this may not constitute a compliance failure, Certigna is committed to rectifying the situation and improving their processes to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:25 UTC Confidence: 0.90
Chronology
  1. Problem identified and reported to technical teams
  2. Halted SSL certificate issuance
  3. Communication with registration authority to stop validation
  4. Deployment of changes to comply with SCT requirements
Participants
Josselin Allemandou Rob Clint Andrew Ryan Sleevi
External References
Similar Local Cases
#1667744 RESOLVED Certificate Misissuance Opened 2020-09-28 · Closed 2023-02-22 · 67% similar
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
#1883416 RESOLVED Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 66% similar
Certigna: TLS certificates with Basic constraint non-critical
#1485413 RESOLVED Certificate Misissuance Opened 2018-08-22 · Closed 2023-02-22 · 57% similar
Certigna: Issuance without respecting CAA records
#1582601 RESOLVED Certificate Misissuance Opened 2019-09-20 · Closed 2023-02-22 · 52% similar
E-Tugra: Invalid DER results in failure to comply with RFC 5280 - Violating string length limit
#1715929 RESOLVED Certificate Misissuance Opened 2021-06-11 · Closed 2023-02-22 · 51% similar
Sectigo: Incorrect EV businessCategory
#1595921 RESOLVED Certificate Misissuance Opened 2019-11-12 · Closed 2023-02-22 · 50% similar
DigiCert: Domain validation skipped
#1674082 RESOLVED Certificate Misissuance Opened 2020-10-29 · Closed 2023-02-22 · 50% similar
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
#1670337 RESOLVED Certificate Misissuance Opened 2020-10-09 · Closed 2024-01-16 · 49% similar
Microsoft PKI Services: Certificate Mis-Issuance, DNSNames must have a valid TLD

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action