← Sectigo cases
Bugzilla #1740493
Certificate Problem Report
Sectigo: Failure to block disallowed LDH labels in domain names
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo identified a failure to block disallowed LDH labels in domain names, which resulted in the issuance of 16 misissued certificates. This issue arose from a misunderstanding of compliance requirements following the implementation of CABF ballot SC48v2. After realizing the oversight, Sectigo deployed a fix and revoked the affected certificates. The incident raised concerns about the processes in place for ensuring compliance and the timeliness of incident reporting.
Chronology
- Relevant section of SC48v2 goes into effect.
- Fix deployed to prevent issuance to prohibited domains.
- SSL Abuse receives report of misissued certificates.
- Revocation of 11 misissued certificates completed.
- Additional 5 misissued certificates revoked.
Participants
Martijn Katerbarg
Ryan Sleevi
Tim Callan
External References
Similar Local Cases
Sectigo: Lack of input validation in stateOrProvinceName
Sectigo: SC45 DCV Reuse Error
Sectigo: DCV Reuse after 825 days
Sectigo: Inadequate DCV
Sectigo: Incorrect locality information
Sectigo: Incorrect OCSP responses
Sectigo: Failure to provide timely incident reports
Sectigo: Misspellings in stateOrProvince or localityName fields