Sectigo reported misissued test certificates from public roots and revoked affected certificates
Sectigo disclosed that it had issued a number of test certificates from trusted public roots with incorrect subject details, and in some cases without proper domain validation. The issue was first triggered by an external report about a QWAC issued to "Test User," after which Sectigo revoked that certificate and began investigating the broader scope. Sectigo later reported that it had found additional affected certificates, revoked known misissued certificates, and temporarily stopped issuing QA-requested certificates while it investigated. The company said it identified root causes in both its QA process and its validation controls, then implemented technical and procedural mitigations, including removing manual DCV permissions, adding automated checks and reporting, and expanding training. By the end of the thread, Sectigo said it had delivered the committed mitigations and Mozilla indicated it would consider closing the bug.
- Sectigo revoked a QWAC issued to the wrong party after receiving an external report.
- Sectigo reported it had identified 38 misissued test certificates and revoked all known affected certificates.
- Sectigo said the code fix preventing manual DCV bypass had been deployed.
- Sectigo said it had completed its research and found a total of 97 affected certificates.
- Sectigo launched additional training for relevant technical employees.
- Community commenter — The reporter said Sectigo appeared to be issuing and revoking certificates with test information in the subject field and linked to crt.sh evidence.
- Sectigo — Sectigo said it had received a report about a QWAC issued to Test User, revoked it, and started investigating other affected certificates.
- Sectigo — Sectigo said it had found recurring QA-process problems, identified 38 affected certificates, revoked known misissued certificates, and disabled manual DCV permissions.
- Sectigo — Sectigo published a detailed analysis describing QA, validation, and compliance failures and said it had suspended QA issuance and implemented remediation steps.
- Sectigo — Sectigo said it had completed its research, shut down internal testing accounts with public-root access, and found 30 additional affected certificates.
- Sectigo — Sectigo posted a timeline stating the incident involved 97 certificates issued between 2019-08-13 and 2021-06-10 and that issuance with incomplete authentication had ceased.
- Mozilla representative — Mozilla said it would consider closing the bug on 2021-10-20 unless there were contrary comments.