DigiCert: Incorrect RegNumber-Org Type combination
DigiCert filed this incident report after its compliance analytics team scanned for potential certificate issues and found certificates where the organizational type did not match the registration number convention. The issue was identified as a missing system logic check to ensure the type of organization matched the registration number, and DigiCert reported that it also detected similar issues with other CAs. DigiCert performed internal review and validation, identified 39 certificates with the condition, and stated that the first certificate was issued on 2019-07-31 and the last on 2021-02-10. DigiCert deployed a system fix on 2021-06-03 to prevent agents from selecting an organizational type that would allow a mismatch with the JOI registration number field, and it reported that a fix associated with QuoVadis was being evaluated. DigiCert stated that the problematic certificates were revoked and that the QuoVadis system fix was applied to block the org type and registration number inconsistency. The bug was then requested for closure, and Mozilla indicated it would be queued for closure unless there were objections.
- DigiCert completed a new scan for mis-matched registration numbers to organizational type and provided results to internal audit for review.
- Internal audit reviewed the identified issues and sent them for validation; DigiCert started revoke alias and customer notifications and ran a comprehensive sweep.
- DigiCert deployed a system fix to enforce consistency between organization type and registration field and prevent the mismatch.
- DigiCert reported consolidated updates: all identified certificates were revoked and the QuoVadis system fix was applied.
- DigiCert — Filed an incident report describing how DigiCert discovered the mismatch, the timeline of its internal investigation, and the planned revocation and system fixes (including QuoVadis evaluation).
- Community commenter — Asked what prompted the scan and what analysis was performed, and requested clarification on the implemented system block and how it works.
- DigiCert — Explained the investigation: a rejected validation request showed mixed registration type and org type, prompting a query; described the fix tying org validation to JOI linter and noted work with QuoVadis engineering.
- Community commenter — Requested that all DigiCert-operated CAs be treated as in-scope for the incident and asked for consolidated timelines for resolution and fixing.
- DigiCert — Provided a consolidated update for all DigiCert-operated CAs: all identified certificates were revoked and the QuoVadis system fix was applied.
- DigiCert — Asked whether anything else was needed and requested closure.
- Mozilla representative — Stated that, unless there were objections, the bug would be queued for closure on 23-June-2021.