← Sectigo cases
Bugzilla #1741026 Certificate Misissuance

Sectigo: Incorrect JOI for federal credit unions

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified a misissuance involving eleven certificates issued to federal credit unions that incorrectly included state-level information in the JOIStateName fields. The issue was discovered during a review of their certificate corpus, leading to the revocation of the affected certificates. Although the initial discovery occurred on October 7, 2021, the reporting of the incident was delayed due to a series of development schedule slips, which Sectigo acknowledged as a mismanagement error. The CA has since implemented programmatic checks to prevent similar misissuances in the future.

Model: gpt-4o-mini Generated: 2026-06-13 20:57 UTC Confidence: 0.90
Chronology
  1. Discovery of misissued certificates
  2. First certificate revoked
  3. Additional certificates revoked
  4. QGIS matching goes into production
  5. Bug scheduled for closure
Participants
Tim Callan Ryan Sleevi Ben Wilson
External References
Similar Local Cases
#1710243 RESOLVED Certificate Misissuance Opened 2021-05-08 · Closed 2023-02-22 · 77% similar
Sectigo: Invalid stateOrProvinceName
#1665763 RESOLVED Certificate Misissuance Opened 2020-09-17 · Closed 2023-02-22 · 73% similar
Sectigo: Failure to revoke within 5 days
#1720744 RESOLVED Certificate Misissuance Opened 2021-07-15 · Closed 2023-02-22 · 72% similar
Sectigo: State name in localityName
#1715929 RESOLVED Certificate Misissuance Opened 2021-06-11 · Closed 2023-02-22 · 70% similar
Sectigo: Incorrect EV businessCategory
#1712120 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 69% similar
Sectigo: Inappropriate subject:serialNumber information in EV certificates obtained through ACME
#1782356 RESOLVED Certificate Misissuance Opened 2022-07-30 · Closed 2023-02-22 · 68% similar
Sectigo: Misspelled city name in localityName field
#1714628 RESOLVED Certificate Misissuance Opened 2021-06-04 · Closed 2023-02-22 · 65% similar
Sectigo: Forbidden Domain Validation Method
#1712188 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 65% similar
Sectigo: test certificates issued from trusted CA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action