← Sectigo cases
Bugzilla #1712188 Certificate Misissuance

Sectigo reported misissued test certificates from public roots and revoked affected certificates

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo disclosed that it had issued a number of test certificates from trusted public roots with incorrect subject details, and in some cases without proper domain validation. The issue was first triggered by an external report about a QWAC issued to "Test User," after which Sectigo revoked that certificate and began investigating the broader scope. Sectigo later reported that it had found additional affected certificates, revoked known misissued certificates, and temporarily stopped issuing QA-requested certificates while it investigated. The company said it identified root causes in both its QA process and its validation controls, then implemented technical and procedural mitigations, including removing manual DCV permissions, adding automated checks and reporting, and expanding training. By the end of the thread, Sectigo said it had delivered the committed mitigations and Mozilla indicated it would consider closing the bug.

Model: gpt-5.4-mini Generated: 2026-06-13 20:58 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.97 43 comments
Chronology
  1. Sectigo revoked a QWAC issued to the wrong party after receiving an external report.
  2. Sectigo reported it had identified 38 misissued test certificates and revoked all known affected certificates.
  3. Sectigo said the code fix preventing manual DCV bypass had been deployed.
  4. Sectigo said it had completed its research and found a total of 97 affected certificates.
  5. Sectigo launched additional training for relevant technical employees.
Thread Activity
  1. Community commenter — The reporter said Sectigo appeared to be issuing and revoking certificates with test information in the subject field and linked to crt.sh evidence.
  2. Sectigo — Sectigo said it had received a report about a QWAC issued to Test User, revoked it, and started investigating other affected certificates.
  3. Sectigo — Sectigo said it had found recurring QA-process problems, identified 38 affected certificates, revoked known misissued certificates, and disabled manual DCV permissions.
  4. Sectigo — Sectigo published a detailed analysis describing QA, validation, and compliance failures and said it had suspended QA issuance and implemented remediation steps.
  5. Sectigo — Sectigo said it had completed its research, shut down internal testing accounts with public-root access, and found 30 additional affected certificates.
  6. Sectigo — Sectigo posted a timeline stating the incident involved 97 certificates issued between 2019-08-13 and 2021-06-10 and that issuance with incomplete authentication had ceased.
  7. Mozilla representative — Mozilla said it would consider closing the bug on 2021-10-20 unless there were contrary comments.
Participants
Community commenter Sectigo Mm representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 100% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1708934 RESOLVED Certificate Misissuance Opened 2021-05-01 · Closed 2023-02-22 · 100% similar
Sectigo: Invalid postalCode field
#1712120 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 100% similar
Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME
#1715024 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-06-07 · Closed 2023-02-22 · 100% similar
Sectigo: Misspellings in stateOrProvince or localityName fields
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 95% similar
Sectigo: Subject field with unvalidated information included in certificates
#1756847 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 95% similar
Sectigo: SC45 DCV Reuse Error
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 95% similar
Sectigo: EV SSL Certificates with incorrect subject details.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action