← Sectigo cases
Bugzilla #1718771
Self Reported Incident
Revocation Issue
Sectigo: DCV Reuse after 825 days
RESOLVED
FIXED
Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Sectigo identified issues related to Domain Control Validation (DCV) reuse exceeding the permitted 825 days, which was discovered during an internal compliance audit. The CA initiated a review of its DCV processes and implemented an audit script to identify affected certificates. As a result, Sectigo revoked a total of 96,002 certificates on July 13, 2021, and continued to investigate further instances of DCV reuse. The CA has since concluded its research on DCV misissuance and reported no additional revocations pending. The case is now resolved.
Chronology
- Sectigo revoked 96,002 certificates for DCV reuse beyond the permitted period.
Thread Activity
- Sectigo — Sectigo announced the initiation of a full review of its DCV components and processes.
- Sectigo — Sectigo reported ongoing investigations into affected certificates and the complexity of the issue.
- Sectigo — Sectigo revoked 160 additional certificates for DCV reuse beyond 825 days.
- Sectigo — Sectigo concluded its DCV misissuance research with no additional revocations pending.
Participants
Sectigo
Community commenter
Thisisntrocket representative
Mozilla representative
External References
Similar Local Cases
Sectigo: Subject field with unvalidated information included in certificates
Sectigo: Failure to block disallowed LDH labels in domain names
Sectigo: Incorrect JOI for federal credit unions
Sectigo: Incorrect OCSP responses
Sectigo: Failure to provide timely incident reports
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates
Sectigo: Lack of input validation in stateOrProvinceName
Sectigo: CPR response issues