Certigna: certificates issued with 2 SCT
Certigna reported that its “Certigna Services CA” and “Certigna Wild CA” issued 126 SSL certificates between April 21 and May 6, 2021 with only 2 SCTs. Certigna stated this did not meet Apple’s certificate transparency policy requirement for using 3 SCTs for certificates with a lifetime between 181 and 398 days. Certigna said it became aware of the issue via a tweet published May 5, 2021 (observed May 6) linking to sslmate’s post about Apple’s new CT policy. After technical teams confirmed non-compliance, Certigna stopped validation of SSL certificate requests and issuance on May 6, and communicated with the registration authority to stop and later reactivate validation. Certigna also deployed a production change to use 3 SCTs for certificates with a lifetime of more than 180 days and initiated an action plan to have certificate managers issue replacements and revoke non-compliant certificates within 5 days if possible. The bug was resolved as INVALID, with commenters stating they did not see a root program compliance violation requiring revocation, while acknowledging the community value of Certigna’s report.
- Certigna issued SSL certificates that used only 2 SCTs (for the relevant lifetime window).
- A tweet about Apple’s new CT policy was published, which Certigna later used to identify the issue.
- Certigna stopped validation/issuance after confirming non-compliance and deployed the change to use 3 SCTs.
- Dhimyotis representative — Created the report stating 126 certificates were issued with 2 SCTs instead of 3 SCTs required by Apple’s CT policy for the relevant certificate lifetime.
- Dhimyotis representative — Provided a timeline: technical confirmation, stopping validation, deploying 3-SCT change, and coordinating with the registration authority and certificate managers for replacement and revocation.
- Sectigo — Argued there was no CA compliance failure requiring revocation and suggested resolving the bug as INVALID.
- Wilsonovi representative — Agreed the bug could be closed as RESOLVED INVALID.
- Mm representative — Agreed it is not strictly a root program compliance violation but appreciated the incident report and asked for more insights.
- Community commenter — Noted the report is useful for learning and asked about the technical constraints and change-management timeline.
- Dhimyotis representative — Responded that Certigna would maintain replacement and revocation efforts, explained deployment delay due to other scheduled website evolution, and described process changes to better meet deadlines.