← Sectigo cases
Bugzilla #1717046 Certificate Misissuance

Sectigo: potentially invalid organizational validation certificates

RESOLVED INVALID Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened based on an external report that Sectigo issued multiple organizational validation (OV) certificates toward Alipay US Inc. The reporter cited Certificate Transparency log entries showing OV certificates for Alipay US Inc, but stated that there were no other OV certificates for the organization and that the only domains covered by the cited certificates (baleines.live, ygmg.vip, and zao.lu) were not controlled by Alipay US Inc. Sectigo’s SSL Abuse and Malware Team responded that the certificates were validated and issued in accordance with the Baseline Requirements and Sectigo policies, and said it would contact Alipay US Inc. to investigate the situation. Mozilla asked the reporter for more details about why they believed the certificates were invalid and whether they had contacted Sectigo’s problem reporting mechanism and received an unsatisfactory response. After Sectigo’s response, Mozilla indicated the case sounded like it could be treated as WontFix/Invalid for now, with an option to revisit if further details were provided. The bug is currently marked RESOLVED with resolution INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:52 UTC Confidence: 0.86 4 comments
Chronology
  1. A report was filed alleging Sectigo issued potentially invalid OV certificates for Alipay US Inc based on Certificate Transparency log entries.
  2. Sectigo’s SSL Abuse and Malware Team responded that the certificates were validated and issued per Baseline Requirements and Sectigo policies.
  3. Mozilla discussed whether the report should be treated as WontFix/Invalid pending further details.
Thread Activity
  1. Nichi representative — Reported that CT logs show multiple OV certificates issued by Sectigo toward Alipay US Inc, but claimed there were no other OV certificates for the organization and that the covered domains were not controlled by Alipay US Inc.
  2. Community commenter — Asked for more details on why the reporter believed the certificates were invalid and whether the reporter had contacted Sectigo’s problem reporting mechanism and received an unsatisfactory response.
  3. Nichi representative — Shared Sectigo SSL Abuse and Malware Team’s response stating the certificates were validated and issued in accordance with Baseline Requirements and Sectigo policies, and that Sectigo would contact Alipay US Inc. to investigate.
  4. Community commenter — Noted that Alipay US, Inc appears to be a legitimate company based on a referenced business registry and suggested the case could be WontFix/Invalid for now, with possible reopening if more details emerged.
Participants
Nichi representative Community commenter Mozilla representative
Similar Local Cases
#1910451 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2024-08-21 · 90% similar
Sectigo: Missing character in subject:organizationName attribute value
#1639518 RESOLVED Certificate Misissuance Opened 2020-05-20 · Closed 2025-08-18 · 87% similar
Sectigo: "unauthorized" OCSP responses
#1590810 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-23 · Closed 2023-02-22 · 77% similar
Sectigo: EV SSL Certificates with incorrect businessCategory
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 76% similar
DigiCert: Invalid localityName
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 76% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 76% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8
#1712188 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 76% similar
Sectigo: test certificates issued from trusted CA
#1649947 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 76% similar
Microsec: Incorrect OCSP Delegated Responder Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action