Sectigo: legacy “Manual DCV” capability misused, leading to DCV misissuance
This case concerns Sectigo certificates that were issued using a legacy “Manual DCV” capability in a way that did not follow compliant DCV validation. Sectigo says it became aware of the problem after receiving a misissued certificate report from another CA on May 19, 2021, and its investigation found four certificates issued to unregistered domains. Sectigo determined that validation employees with sufficient rights could record DCV as having occurred for a specific domain by misusing the legacy “Manual DCV” capability. Sectigo disabled “Manual DCV” permissions for all employees regardless of role or level on March 21 (as described in the thread) and deployed a permanent code fix removing Manual DCV from production on June 7. Sectigo then deployed a comprehensive code fix to address known DCV errors and ran queries to identify additional affected certificates. The investigation concluded with revocation of eleven additional certificates for Manual DCV, bringing the total to fifteen affected certificates, and Sectigo stated its systems cannot issue certificates with this problem. Mozilla indicated it would close the incident on or about 18-Aug-2021, and the bug is marked RESOLVED with resolution FIXED.
- Sectigo received a misissued certificate report from another CA and began investigating Manual DCV-related issuance issues.
- Sectigo deployed a permanent code fix removing the legacy “Manual DCV” functionality from production.
- Sectigo revoked eleven additional certificates affected by Manual DCV and stated the investigation was complete.
- Mozilla planned closure of the incident on or about 18-Aug-2021.
- Sectigo — Opened the bug to discuss the DCV misissuance portion involving misuse of legacy “Manual DCV,” describing the investigation and actions taken to disable and remove Manual DCV.
- Sectigo — Said the investigation continued and was intertwined with bug 1718771, referring to that bug for more detail.
- Sectigo — Noted that revocation batches would be announced as confirmed and that Manual DCV results were still being investigated.
- Sectigo — Reported revocation of eleven certificates with Manual DCV and stated the investigation was complete, totaling fifteen affected certificates.
- Sectigo — Provided a structured incident narrative including how Sectigo became aware, the timeline, and that Manual DCV capability was removed so systems cannot issue certificates with the problem.
- Sectigo — Said Sectigo would monitor the bug for questions or comments.
- Sectigo — Asked whether Mozilla was ready to close the bug, stating Sectigo believed the issue was resolved.
- Mozilla representative — Planned to close the incident on or about next Wed (18-Aug-2021).