← Sectigo cases
Bugzilla #1723263
Certificate Misissuance
Sectigo: IP Address Domain Validation Failure
RESOLVED
INVALID
Sectigo
AI Summary
This case involves a report of mis-issued certificates by Sectigo due to BGP hijacking. The reporter demonstrated that by hijacking an IP prefix, they were able to obtain certificates for those IPs without legitimate ownership. While the discussion highlighted the potential for mis-issuance, it was concluded that this issue is not unique to Sectigo, as BGP hijacking poses a broader risk to both IP address and DNS validation methods. The case was ultimately marked as resolved with an invalid status, indicating that the concerns raised were acknowledged but not deemed a compliance incident.
Chronology
- Initial report of mis-issued certificates due to BGP hijacking.
- Further investigation revealed additional successful certificate issuances.
- Discussion concluded with the case being marked as resolved/invalid.
Participants
Charles Wang
Tim Callan
Ryan Sleevi
Andrew Ayer
External References
Similar Local Cases
Sectigo: Failure to revoke within 5 days
Sectigo: Forbidden Domain Validation Method
Sectigo: test certificates issued from trusted CA
Sectigo: Incorrect EV businessCategory
Sectigo: Invalid stateOrProvinceName
Sectigo: Incorrect JOI for federal credit unions
Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME
Sectigo: State name in localityName