Sectigo: IP Address Domain Validation Failure
The reporter (Charles Wang) described an IP address domain validation failure scenario involving Sectigo-issued DV IP certificates. He stated that by hijacking an IP prefix via BGP announcement and then applying the validation value, Sectigo issued certificates to the hijacked IP prefixes, and he provided related mis-issued certificate links on crt.sh. He argued that this could allow attackers to pass domain control validation without legitimate IP address ownership and suggested changing issuance guidelines to require RPKI verification before issuing IP certificates. Mozilla staff (Ryan Sleevi) responded that BGP hijacking can bypass both IP address validation and DNS validation, and that this is within the known threat model for TLS rather than a Sectigo-specific compliance incident. Another Mozilla participant cited Mozilla Root Store Policy 2.2(4) and asked whether the reporter had reported the certificates to Sectigo’s problem reporting address and whether Sectigo revoked them within 24 hours as required by BR 4.9.9.1. The issue was ultimately closed as Resolved/Invalid, with Mozilla encouraging discussion of general mitigations outside the CA issue process.
- Bug 1723263 was opened reporting that Sectigo issued DV IP certificates after BGP hijacking enabled passing IP address domain control validation.
- Mozilla staff reviewed the report and determined it did not constitute a CA compliance incident, closing the issue as Resolved/Invalid.
- The bug record was last changed while remaining marked INVALID/RESOLVED.
- Nekollc representative — Reported that hijacking an IP prefix via BGP announcement allowed passing DCV and resulted in Sectigo issuing certificates to the hijacked prefixes, including crt.sh links.
- Nekollc representative — Updated that additional IP tests also succeeded and stated he would continue investigating and return with evidence and solutions.
- Community commenter — Said it was unclear this was a Sectigo-specific issue because BGP hijacking can bypass IP or DNS validation, and noted TLS does not defend against BGP hijacks; closed as Resolved/Invalid.
- Mm representative — Cited Mozilla Root Store Policy 2.2(4) and asked whether the certificates were reported to Sectigo for revocation within 24 hours per BR 4.9.9.1.
- Nekollc representative — Agreed it was not a single Sectigo issue but argued it should be prevented for IP certificates and discussed potential additional limits beyond CAA.
- Nekollc representative — Responded that CAA works for domain names but not IP addresses, and suggested more limits for IP certificates.
- Community commenter — Clarified that CAA does not work around the issue and reiterated that TLS does not defend against BGP hijacking for DNS or IP addresses.