← Sectigo cases
Bugzilla #1710243
Certificate Misissuance
Sectigo: Invalid stateOrProvinceName
RESOLVED
FIXED
Sectigo
AI Summary
This case addresses the misissuance of certificates by Sectigo that included invalid stateOrProvinceName values, specifically 'Moldova' and 'Malta'. The issue was first reported on May 8, 2021, and Sectigo acknowledged the problem, stating that these values were not aligned with their new ISO 3166-2 based lookup table. Following community discussions and a review of their practices, Sectigo decided to revoke the affected certificates. The revocation of six certificates was completed by May 21, 2021, and the CA has since implemented measures to prevent similar misissuances in the future.
Chronology
- Initial report of certificate with invalid stateOrProvinceName
- Additional certificates with invalid stateOrProvinceName reported
- Sectigo announces revocation of affected certificates
- Revocation of six certificates completed
Participants
Michel Le Bihan
Rob Stradling
Tim Callan
George Fozzie
Ryan Sleevi
Ben Wilson
Similar Local Cases
Sectigo: Incorrect JOI for federal credit unions
Sectigo: Failure to revoke within 5 days
Sectigo: Incorrect EV businessCategory
Sectigo: State name in localityName
Sectigo: Forbidden Domain Validation Method
Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME
Sectigo: Misspelled city name in localityName field
Sectigo: test certificates issued from trusted CA