← Sectigo cases
Bugzilla #1740493 Certificate Problem Report

Sectigo: Failure to block disallowed LDH labels in domain names

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified a failure to block disallowed LDH labels in domain names, which resulted in the issuance of 16 misissued certificates. This issue arose from a misunderstanding of compliance requirements following the implementation of CABF ballot SC48v2. After realizing the oversight, Sectigo deployed a fix and revoked the affected certificates. The incident raised concerns about the processes in place for ensuring compliance and the timeliness of incident reporting.

Model: gpt-4o-mini Generated: 2026-06-13 20:57 UTC Confidence: 0.90
Chronology
  1. Relevant section of SC48v2 goes into effect.
  2. Fix deployed to prevent issuance to prohibited domains.
  3. SSL Abuse receives report of misissued certificates.
  4. Revocation of 11 misissued certificates completed.
  5. Additional 5 misissued certificates revoked.
Participants
Martijn Katerbarg Ryan Sleevi Tim Callan
External References
Similar Local Cases
#1645686 RESOLVED Certificate Problem Report Opened 2020-06-14 · Closed 2023-02-22 · 69% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1756847 RESOLVED Certificate Problem Report Opened 2022-02-23 · Closed 2023-02-22 · 68% similar
Sectigo: SC45 DCV Reuse Error
#1718771 RESOLVED Certificate Problem Report Opened 2021-06-30 · Closed 2023-02-22 · 67% similar
Sectigo: DCV Reuse after 825 days
#1694233 RESOLVED Certificate Problem Report Opened 2021-02-22 · Closed 2023-02-22 · 66% similar
Sectigo: Inadequate DCV
#1714193 RESOLVED Certificate Problem Report Opened 2021-06-02 · Closed 2023-02-22 · 66% similar
Sectigo: Incorrect locality information
#1763203 RESOLVED Certificate Problem Report Opened 2022-04-05 · Closed 2023-02-22 · 66% similar
Sectigo: Incorrect OCSP responses
#1563579 RESOLVED Certificate Problem Report Opened 2019-07-04 · Closed 2023-02-22 · 66% similar
Sectigo: Failure to provide timely incident reports
#1715024 RESOLVED Certificate Problem Report Opened 2021-06-07 · Closed 2023-02-22 · 65% similar
Sectigo: Misspellings in stateOrProvince or localityName fields

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action