Sectigo: potentially invalid organizational validation certificates
The bug was opened based on an external report that Sectigo issued multiple organizational validation (OV) certificates toward Alipay US Inc. The reporter cited Certificate Transparency log entries showing OV certificates for Alipay US Inc, but stated that there were no other OV certificates for the organization and that the only domains covered by the cited certificates (baleines.live, ygmg.vip, and zao.lu) were not controlled by Alipay US Inc. Sectigo’s SSL Abuse and Malware Team responded that the certificates were validated and issued in accordance with the Baseline Requirements and Sectigo policies, and said it would contact Alipay US Inc. to investigate the situation. Mozilla asked the reporter for more details about why they believed the certificates were invalid and whether they had contacted Sectigo’s problem reporting mechanism and received an unsatisfactory response. After Sectigo’s response, Mozilla indicated the case sounded like it could be treated as WontFix/Invalid for now, with an option to revisit if further details were provided. The bug is currently marked RESOLVED with resolution INVALID.
- A report was filed alleging Sectigo issued potentially invalid OV certificates for Alipay US Inc based on Certificate Transparency log entries.
- Sectigo’s SSL Abuse and Malware Team responded that the certificates were validated and issued per Baseline Requirements and Sectigo policies.
- Mozilla discussed whether the report should be treated as WontFix/Invalid pending further details.
- Nichi representative — Reported that CT logs show multiple OV certificates issued by Sectigo toward Alipay US Inc, but claimed there were no other OV certificates for the organization and that the covered domains were not controlled by Alipay US Inc.
- Community commenter — Asked for more details on why the reporter believed the certificates were invalid and whether the reporter had contacted Sectigo’s problem reporting mechanism and received an unsatisfactory response.
- Nichi representative — Shared Sectigo SSL Abuse and Malware Team’s response stating the certificates were validated and issued in accordance with Baseline Requirements and Sectigo policies, and that Sectigo would contact Alipay US Inc. to investigate.
- Community commenter — Noted that Alipay US, Inc appears to be a legitimate company based on a referenced business registry and suggested the case could be WontFix/Invalid for now, with possible reopening if more details emerged.