← Sectigo cases
Bugzilla #1712120 Certificate Misissuance

Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified a misissuance of Extended Validation (EV) TLS certificates where the subject:serialNumber field incorrectly contained dates of incorporation instead of the appropriate registration numbers. This issue was discovered during an internal audit, leading to a series of corrective actions including disabling access to the EV ACME server and revoking 204 affected certificates. The root cause was traced to a coding bug in the ACME order processing system, which failed to retrieve the correct registration number from the database. Sectigo has since implemented automated testing to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 20:58 UTC Confidence: 0.95
Chronology
  1. Internal audit discovers misissuance of EV TLS certificates.
  2. List of affected certificates generated.
  3. All affected certificates revoked.
  4. Automated tests for ACME issuance added.
Participants
Tim Callan Ryan Sleevi Nikola Maksimovic
External References
Similar Local Cases
#1720744 RESOLVED Certificate Misissuance Opened 2021-07-15 · Closed 2023-02-22 · 71% similar
Sectigo: State name in localityName
#1741026 RESOLVED Certificate Misissuance Opened 2021-11-13 · Closed 2023-02-22 · 69% similar
Sectigo: Incorrect JOI for federal credit unions
#1715929 RESOLVED Certificate Misissuance Opened 2021-06-11 · Closed 2023-02-22 · 68% similar
Sectigo: Incorrect EV businessCategory
#1710243 RESOLVED Certificate Misissuance Opened 2021-05-08 · Closed 2023-02-22 · 66% similar
Sectigo: Invalid stateOrProvinceName
#1712188 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 66% similar
Sectigo: test certificates issued from trusted CA
#1714628 RESOLVED Certificate Misissuance Opened 2021-06-04 · Closed 2023-02-22 · 64% similar
Sectigo: Forbidden Domain Validation Method
#1665763 RESOLVED Certificate Misissuance Opened 2020-09-17 · Closed 2023-02-22 · 64% similar
Sectigo: Failure to revoke within 5 days
#1736064 RESOLVED Certificate Misissuance Opened 2021-10-15 · Closed 2023-02-22 · 64% similar
Sectigo: Subject field with unvalidated information included in certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action