← Sectigo cases
Bugzilla #1740493 Ca Certificate Compliance Certificate Misissuance Self Reported Incident

Sectigo: Failure to block disallowed LDH labels in domain names

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a compliance issue it discovered during its own review of CABF ballots and its response to them. The problem was that its system was not rejecting certain disallowed Reserved LDH labels that are not P-Labels in domain names, despite SC48v2 - Domain Name and IP Address Encoding taking effect on 2021-10-01. Sectigo stated that it deployed a patch on 2021-10-09 to make it compliant with the SC48v2 changes and that it stopped issuing certificates with the problem. After SSL Abuse reported 9 misissued certificates on 2021-10-11, Sectigo investigated and found 11 misissued certificates, then completed revocation of those on 2021-10-16. Sectigo later found an additional 5 misissued certificates and revoked them on 2021-10-24. The bug was resolved as FIXED, and Sectigo said it would continue monitoring for questions or comments before proposing closure; Mozilla closed the bug on 2021-12-17 unless objections were raised.

Model: gpt-5.4-nano Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:55 UTC Confidence: 0.86 10 comments
Chronology
  1. SC48v2 - Domain Name and IP Address Encoding took effect, allowing only P-Labels or Non-Reserved LDH Labels as Domain Labels.
  2. Sectigo deployed a fix intended to make it compliant with SC48v2 domain label requirements.
  3. Sectigo completed revocation of 11 misissued certificates.
  4. Sectigo revoked an additional 5 misissued certificates.
Thread Activity
  1. Sectigo — Created the bug and provided a detailed incident narrative describing how Sectigo became aware of the issue, the affected certificates, and the revocation actions taken.
  2. Community commenter — Raised questions about the incident timeline precision, why misissuance was discovered externally, the compliance process used for SC48v2, and the delay in reporting the incident to Mozilla.
  3. Sectigo — Responded to the concerns, including clarifications about timeline timestamping and the sequence of discovery and revocation, and described process changes such as tracking exact timelines and adding a reporting deadline two weeks after discovery.
  4. Community commenter — Continued discussion, expressing concern about incident reporting practices and compliance transparency based on the thread’s facts and comparisons to other bugs.
  5. Sectigo — Acknowledged the comment and said Sectigo was working on a detailed response.
  6. Sectigo — Provided a corrected, more precise timeline for report and revocation steps and described additional internal process controls for incident reporting.
  7. Sectigo — Stated there were no further updates and that Sectigo would continue monitoring the bug.
  8. Sectigo — Proposed closure of the bug due to no further questions or comments.
  9. Mozilla representative — Announced closure of the bug on 2021-12-17 unless there were objections.
Participants
Sectigo Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 100% similar
Sectigo: Incorrect OCSP responses
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 100% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1620561 RESOLVED Self Reported Incident Opened 2020-03-06 · Closed 2023-02-22 · 100% similar
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 100% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 100% similar
Sectigo: CPR response issues
#1708934 RESOLVED Certificate Misissuance Opened 2021-05-01 · Closed 2023-02-22 · 100% similar
Sectigo: Invalid postalCode field
#1712120 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 100% similar
Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action