← Sectigo cases
Bugzilla #1720744
Certificate Misissuance
Sectigo: State name in localityName
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo identified an issue where six certificates were issued with 'Suffolk' listed in both the stateOrProvinceName and localityName fields, leading to a misissuance. The problem was discovered during an internal investigation on July 9, 2021, and the affected certificates were revoked by July 13, 2021. The error was attributed to a former RA's mistake and a lack of programmatic controls. Sectigo has since implemented measures to prevent similar issues, including plans to eliminate the localityName field from future certificates.
Chronology
- Certificates discovered with incorrect locality information
- Two of the affected certificates expire
- Remaining four certificates revoked
Participants
Tim Callan
Ryan Sleevi
Similar Local Cases
Sectigo: Incorrect EV businessCategory
Sectigo: Incorrect JOI for federal credit unions
Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME
Sectigo: Invalid stateOrProvinceName
Sectigo: test certificates issued from trusted CA
Sectigo: Failure to revoke within 5 days
Sectigo: Forbidden Domain Validation Method
Sectigo: Subject field with unvalidated information included in certificates