← Sectigo cases
Bugzilla #1736064
Certificate Misissuance
Sectigo: Subject field with unvalidated information included in certificates
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo identified a misissuance issue where OV and EV certificates contained the postOfficeBox subject field, which is not compliant with the EV Guidelines. The problem was discovered during an internal code review, leading to the revocation of 453 affected certificates. A code fix was deployed to prevent future issuance of such certificates. The affected certificates were scheduled for revocation on October 16, 2021, and the issue has since been resolved with the implementation of stricter validation checks.
Chronology
- Internal code review reveals potential to issue certificates with postOfficeBox.
- Fix deployed.
- Investigation of corpus of certificates begins.
- Revocation of all affected certificates scheduled.
- Allowed Subject Fields release went live.
Participants
Tim Callan
darkkiller@gmail.com
matthias@thisisntrocket.science
ryan.sleevi@gmail.com
bwilson@mozilla.com
External References
Similar Local Cases
Telekom Security: Certificate with invalid FQDN
Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME
Sectigo: State name in localityName
Sectigo: Incorrect JOI for federal credit unions
Sectigo: Incorrect EV businessCategory
Sectigo: Invalid stateOrProvinceName
Sectigo: Misspelled city name in localityName field
SSL.com: Wildcard DV certificate issued with a non-validated domain name