← Sectigo cases
Bugzilla #1732484
Certificate Problem Report
Sectigo: Truncated registration numbers in EV certificates
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo identified a truncation issue affecting some of its EV certificates, where the subject:serialNumber values were limited to 25 characters. This was discovered during an investigation prompted by a related issue reported by DigiCert. Affected certificates were issued between September 16, 2019, and July 13, 2021. Following the identification of the problem, Sectigo deployed a fix to allow for a maximum of 64 characters and scheduled revocation of the affected certificates. The revocation was successfully completed on September 25, 2021.
Chronology
- DigiCert bug 1727963 reported.
- Code review reveals truncation issue.
- Fix deployed to prevent truncation.
- Scheduled revocation of affected certificates completed.
Participants
Tim Callan
External References
Similar Local Cases
Sectigo: Invalid postalCode field
Sectigo: Missing registration numbers in EV certificates
Sectigo: Mojibake in certificate Subject fields
Sectigo: SC45 DCV Reuse Error
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
Sectigo: 2020 failure to respond to CPRs discovered
Sectigo: OV reuse data applied for wrong organization
Sectigo: "Manual DCV" method used