Sectigo: Failure to block disallowed LDH labels in domain names
Sectigo reported a compliance issue it discovered during its own review of CABF ballots and its response to them. The problem was that its system was not rejecting certain disallowed Reserved LDH labels that are not P-Labels in domain names, despite SC48v2 - Domain Name and IP Address Encoding taking effect on 2021-10-01. Sectigo stated that it deployed a patch on 2021-10-09 to make it compliant with the SC48v2 changes and that it stopped issuing certificates with the problem. After SSL Abuse reported 9 misissued certificates on 2021-10-11, Sectigo investigated and found 11 misissued certificates, then completed revocation of those on 2021-10-16. Sectigo later found an additional 5 misissued certificates and revoked them on 2021-10-24. The bug was resolved as FIXED, and Sectigo said it would continue monitoring for questions or comments before proposing closure; Mozilla closed the bug on 2021-12-17 unless objections were raised.
- SC48v2 - Domain Name and IP Address Encoding took effect, allowing only P-Labels or Non-Reserved LDH Labels as Domain Labels.
- Sectigo deployed a fix intended to make it compliant with SC48v2 domain label requirements.
- Sectigo completed revocation of 11 misissued certificates.
- Sectigo revoked an additional 5 misissued certificates.
- Sectigo — Created the bug and provided a detailed incident narrative describing how Sectigo became aware of the issue, the affected certificates, and the revocation actions taken.
- Community commenter — Raised questions about the incident timeline precision, why misissuance was discovered externally, the compliance process used for SC48v2, and the delay in reporting the incident to Mozilla.
- Sectigo — Responded to the concerns, including clarifications about timeline timestamping and the sequence of discovery and revocation, and described process changes such as tracking exact timelines and adding a reporting deadline two weeks after discovery.
- Community commenter — Continued discussion, expressing concern about incident reporting practices and compliance transparency based on the thread’s facts and comparisons to other bugs.
- Sectigo — Acknowledged the comment and said Sectigo was working on a detailed response.
- Sectigo — Provided a corrected, more precise timeline for report and revocation steps and described additional internal process controls for incident reporting.
- Sectigo — Stated there were no further updates and that Sectigo would continue monitoring the bug.
- Sectigo — Proposed closure of the bug due to no further questions or comments.
- Mozilla representative — Announced closure of the bug on 2021-12-17 unless there were objections.