Sectigo: Misspellings in stateOrProvince or localityName fields
Sectigo identified and resolved issues related to misspellings in the stateOrProvince and localityName fields of nine certificates. The problem was first reported on May 19, 2020, leading to a swift investigation and acknowledgment of errors. All affected certificates were revoked by May 23, 2020. The root cause was attributed to human error during the issuance process, particularly in the localityName field, which lacks systematic checks. Sectigo has since implemented a lookup table for the stateOrProvince field to prevent future occurrences, although challenges remain for the localityName field due to its variable nature.
- Certificates reported to Sectigo's abuse address.
- First certificate revoked.
- All remaining certificates revoked.