← Sectigo cases
Bugzilla #1723263 Certificate Problem Report

Sectigo: IP Address Domain Validation Failure

RESOLVED INVALID Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The reporter (Charles Wang) described an IP address domain validation failure scenario involving Sectigo-issued DV IP certificates. He stated that by hijacking an IP prefix via BGP announcement and then applying the validation value, Sectigo issued certificates to the hijacked IP prefixes, and he provided related mis-issued certificate links on crt.sh. He argued that this could allow attackers to pass domain control validation without legitimate IP address ownership and suggested changing issuance guidelines to require RPKI verification before issuing IP certificates. Mozilla staff (Ryan Sleevi) responded that BGP hijacking can bypass both IP address validation and DNS validation, and that this is within the known threat model for TLS rather than a Sectigo-specific compliance incident. Another Mozilla participant cited Mozilla Root Store Policy 2.2(4) and asked whether the reporter had reported the certificates to Sectigo’s problem reporting address and whether Sectigo revoked them within 24 hours as required by BR 4.9.9.1. The issue was ultimately closed as Resolved/Invalid, with Mozilla encouraging discussion of general mitigations outside the CA issue process.

Model: gpt-5.4-nano Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:54 UTC Confidence: 0.86 7 comments
Chronology
  1. Bug 1723263 was opened reporting that Sectigo issued DV IP certificates after BGP hijacking enabled passing IP address domain control validation.
  2. Mozilla staff reviewed the report and determined it did not constitute a CA compliance incident, closing the issue as Resolved/Invalid.
  3. The bug record was last changed while remaining marked INVALID/RESOLVED.
Thread Activity
  1. Nekollc representative — Reported that hijacking an IP prefix via BGP announcement allowed passing DCV and resulted in Sectigo issuing certificates to the hijacked prefixes, including crt.sh links.
  2. Nekollc representative — Updated that additional IP tests also succeeded and stated he would continue investigating and return with evidence and solutions.
  3. Community commenter — Said it was unclear this was a Sectigo-specific issue because BGP hijacking can bypass IP or DNS validation, and noted TLS does not defend against BGP hijacks; closed as Resolved/Invalid.
  4. Mm representative — Cited Mozilla Root Store Policy 2.2(4) and asked whether the certificates were reported to Sectigo for revocation within 24 hours per BR 4.9.9.1.
  5. Nekollc representative — Agreed it was not a single Sectigo issue but argued it should be prevented for IP certificates and discussed potential additional limits beyond CAA.
  6. Nekollc representative — Responded that CAA works for domain names but not IP addresses, and suggested more limits for IP certificates.
  7. Community commenter — Clarified that CAA does not work around the issue and reiterated that TLS does not defend against BGP hijacking for DNS or IP addresses.
Participants
Nekollc representative Sectigo Community commenter Mm representative
Similar Local Cases
#1648717 RESOLVED Certificate Problem Report Opened 2020-06-26 · Closed 2023-02-22 · 62% similar
Sectigo: Failure to provide a preliminary report within 24 hours.
#1717046 RESOLVED Certificate Misissuance Opened 2021-06-17 · Closed 2022-11-14 · 54% similar
Sectigo: potentially invalid organizational validation certificates
#1639518 RESOLVED Certificate Misissuance Opened 2020-05-20 · Closed 2025-08-18 · 52% similar
Sectigo: "unauthorized" OCSP responses
#1712188 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 49% similar
Sectigo: test certificates issued from trusted CA
#1597948 RESOLVED Certificate Problem Report Opened 2019-11-20 · Closed 2024-06-30 · 45% similar
Sectigo: Missing Intermediate CA Certificate in Audit - D-TRUST CA 2-1 2015
#1910451 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2024-08-21 · 44% similar
Sectigo: Missing character in subject:organizationName attribute value
#1793787 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Repository Issue Opened 2022-10-05 · Closed 2023-02-22 · 43% similar
Sectigo: Non-existent hostname in CDP and AIA URLs
#1912225 RESOLVED Revocation Issue Opened 2024-08-08 · Closed 2024-09-26 · 43% similar
Sectigo: HTML encoded characters in subject attribute values

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action