← Sectigo cases
Bugzilla #1718579
Certificate Problem Report
Sectigo: "Manual DCV" method used
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo identified issues related to the misuse of the legacy 'Manual DCV' method, which led to the issuance of certificates without proper validation. An investigation revealed that 15 certificates were affected, with some issued to unregistered domains. The company has since disabled the Manual DCV functionality and revoked the problematic certificates. The resolution involved a comprehensive code fix and ongoing monitoring to prevent future occurrences.
Chronology
- Received a misissued certificate report from another CA.
- Deployed a code update to remove Manual DCV functionality.
- Revoked eleven additional certificates with Manual DCV.
- Proposed to close the bug after thorough community communication.
Participants
Tim Callan
Ben Wilson
External References
Similar Local Cases
Sectigo: Misspellings in stateOrProvince or localityName fields
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
Sectigo: Mojibake in certificate Subject fields
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
Sectigo: 2020 failure to respond to CPRs discovered
Sectigo: Inadequate DCV
Sectigo: ZeroSSL: failure to revoke within 24 hours
Sectigo: Invalid postalCode field