← Sectigo cases
Bugzilla #1712120 Certificate Misissuance

Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo disclosed a compliance issue involving Extended Validation (EV) TLS certificates that incorrectly included dates of incorporation or registration in the subject:serialNumber field instead of the correct registration numbers. This issue was discovered during an internal audit on May 5, 2021, and was attributed to a coding bug in their ACME order processing system. Following the identification of the problem, Sectigo disabled access to their EV ACME server to prevent further misissuance, revoked all affected certificates by May 10, 2021, and implemented a fix to the underlying software bug. The CA has since ceased issuing non-compliant certificates and has taken steps to improve their QA processes to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 20:58 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.90 23 comments
Chronology
  1. Internal audit discovers misissuance of EV TLS certificates.
  2. All affected certificates revoked.
  3. Automated tests for ACME issuance implemented.
Thread Activity
  1. Sectigo — Created attachment detailing the incident and actions taken.
  2. Sectigo — Provided a report on the incident, including root causes and mitigation steps.
  3. Sectigo — Completed ACME automation project and shared details of the automated test suite.
Participants
Sectigo Community commenter Mozilla representative
External References
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 100% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1708934 RESOLVED Certificate Misissuance Opened 2021-05-01 · Closed 2023-02-22 · 100% similar
Sectigo: Invalid postalCode field
#1712188 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 100% similar
Sectigo: test certificates issued from trusted CA
#1715024 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-06-07 · Closed 2023-02-22 · 100% similar
Sectigo: Misspellings in stateOrProvince or localityName fields
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 99% similar
Sectigo: Subject field with unvalidated information included in certificates
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 97% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1710243 RESOLVED Certificate Misissuance Opened 2021-05-08 · Closed 2023-02-22 · 97% similar
Sectigo: Invalid stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action