Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME
Sectigo disclosed a compliance issue involving Extended Validation (EV) TLS certificates that incorrectly included dates of incorporation or registration in the subject:serialNumber field instead of the correct registration numbers. This issue was discovered during an internal audit on May 5, 2021, and was attributed to a coding bug in their ACME order processing system. Following the identification of the problem, Sectigo disabled access to their EV ACME server to prevent further misissuance, revoked all affected certificates by May 10, 2021, and implemented a fix to the underlying software bug. The CA has since ceased issuing non-compliant certificates and has taken steps to improve their QA processes to prevent similar issues in the future.
- Internal audit discovers misissuance of EV TLS certificates.
- All affected certificates revoked.
- Automated tests for ACME issuance implemented.
- Sectigo — Created attachment detailing the incident and actions taken.
- Sectigo — Provided a report on the incident, including root causes and mitigation steps.
- Sectigo — Completed ACME automation project and shared details of the automated test suite.