← Sectigo cases
Bugzilla #1736064 Ca Certificate Compliance Certificate Misissuance Self Reported Incident

Sectigo: Subject field with unvalidated information included in certificates

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo discovered that its systems had the potential to issue OV and EV certificates containing the postOfficeBox subject field, which is not permissible under current guidelines. This issue was identified during an internal code review on September 30, 2021. Following the discovery, Sectigo deployed a fix on October 10, 2021, and began investigating affected certificates. A total of 453 certificates were identified, with 428 OV and 25 EV certificates requiring revocation. The revocation of these certificates was scheduled for October 16, 2021. Sectigo has since implemented measures to prevent further issuance of certificates with unvalidated information.

Model: gpt-4o-mini Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:55 UTC Confidence: 0.90 25 comments
Chronology
  1. Internal code review reveals potential to issue certificates with postOfficeBox.
  2. Fix deployed to prevent issuance of certificates with postOfficeBox.
  3. Revocation of affected certificates scheduled.
Thread Activity
  1. Sectigo — Created attachment detailing the issue with postOfficeBox subject field.
  2. Community commenter — Requested clarification on a specific certificate not included in the attachment.
  3. Sectigo — Created a corrected attachment with additional details on affected certificates.
  4. Sectigo — Discussed the importance of unique identifiers for certificates.
  5. Sectigo — Identified additional noncompliant EV certificates and scheduled revocation.
  6. Sectigo — Confirmed that the remediation for the issue was completed.
Participants
Sectigo Community commenter Mozilla representative
External References
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 100% similar
Sectigo: Incorrect JOI for federal credit unions
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 100% similar
Sectigo: CPR response issues
#1715024 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-06-07 · Closed 2023-02-22 · 100% similar
Sectigo: Misspellings in stateOrProvince or localityName fields
#1718771 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2023-02-22 · 100% similar
Sectigo: DCV Reuse after 825 days
#1712120 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 99% similar
Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 98% similar
Sectigo: EV SSL Certificates with incorrect subject details.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action