← Certigna cases
Bugzilla #1709896 Certificate Misissuance

Certigna: certificates issued with 2 SCT

RESOLVED INVALID Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Certigna reported that its “Certigna Services CA” and “Certigna Wild CA” issued 126 SSL certificates between April 21 and May 6, 2021 with only 2 SCTs. Certigna stated this did not meet Apple’s certificate transparency policy requirement for using 3 SCTs for certificates with a lifetime between 181 and 398 days. Certigna said it became aware of the issue via a tweet published May 5, 2021 (observed May 6) linking to sslmate’s post about Apple’s new CT policy. After technical teams confirmed non-compliance, Certigna stopped validation of SSL certificate requests and issuance on May 6, and communicated with the registration authority to stop and later reactivate validation. Certigna also deployed a production change to use 3 SCTs for certificates with a lifetime of more than 180 days and initiated an action plan to have certificate managers issue replacements and revoke non-compliant certificates within 5 days if possible. The bug was resolved as INVALID, with commenters stating they did not see a root program compliance violation requiring revocation, while acknowledging the community value of Certigna’s report.

Model: gpt-5.4-nano Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 18:21 UTC Confidence: 0.50 7 comments
Chronology
  1. Certigna issued SSL certificates that used only 2 SCTs (for the relevant lifetime window).
  2. A tweet about Apple’s new CT policy was published, which Certigna later used to identify the issue.
  3. Certigna stopped validation/issuance after confirming non-compliance and deployed the change to use 3 SCTs.
Thread Activity
  1. Dhimyotis representative — Created the report stating 126 certificates were issued with 2 SCTs instead of 3 SCTs required by Apple’s CT policy for the relevant certificate lifetime.
  2. Dhimyotis representative — Provided a timeline: technical confirmation, stopping validation, deploying 3-SCT change, and coordinating with the registration authority and certificate managers for replacement and revocation.
  3. Sectigo — Argued there was no CA compliance failure requiring revocation and suggested resolving the bug as INVALID.
  4. Wilsonovi representative — Agreed the bug could be closed as RESOLVED INVALID.
  5. Mm representative — Agreed it is not strictly a root program compliance violation but appreciated the incident report and asked for more insights.
  6. Community commenter — Noted the report is useful for learning and asked about the technical constraints and change-management timeline.
  7. Dhimyotis representative — Responded that Certigna would maintain replacement and revocation efforts, explained deployment delay due to other scheduled website evolution, and described process changes to better meet deadlines.
Participants
Dhimyotis representative Sectigo Wilsonovi representative Mm representative Community commenter
External References
Similar Local Cases
#1774171 RESOLVED Certificate Misissuance Opened 2022-06-14 · Closed 2023-02-22 · 62% similar
Certigna: Precertificate with a validity period greater than 398-days
#1485413 RESOLVED Ca Certificate Compliance Opened 2018-08-22 · Closed 2023-02-22 · 52% similar
Certigna: Issuance without respecting CAA records
#1667744 RESOLVED Self Reported Incident Opened 2020-09-28 · Closed 2023-02-22 · 48% similar
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
#1838667 RESOLVED Certificate Misissuance Opened 2023-06-15 · Closed 2023-07-05 · 42% similar
Let's Encrypt: Duplicate Serial Numbers
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 42% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 41% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8
#1669594 RESOLVED Certificate Misissuance Opened 2020-10-06 · Closed 2023-02-22 · 41% similar
IdenTrust: Issuance of Subordinate CA’s Without EKU
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 41% similar
Certigna: TLS certificates with Basic constraint non-critical

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action