← Sectigo cases
Bugzilla #1741026 Ca Certificate Compliance Revocation Issue Self Reported Incident

Sectigo: Incorrect JOI for federal credit unions

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a compliance problem it discovered while researching its own corpus of certificates for possible misissuance. The CA found eleven certificates issued to U.S. federal credit unions that included jOIStateName fields containing local state names; Sectigo stated that for federal credit unions, JOIStateName is improper and should be omitted. Sectigo said it scheduled the initially discovered certificate for revocation on October 7, then queried for additional affected certificates and revoked the additional certificates after they were found. Sectigo also stated it programmatically blocked this form of misissuance and announced the release in Bug 1724476 comment 12. In response to discussion about delayed reporting, Sectigo explained that it initially planned to include the report with an upcoming QGIS matching release, but the release slipped multiple times due to COVID-19 absenteeism and scheduling decisions, and Sectigo acknowledged that it should have proceeded with reporting earlier. The bug is marked RESOLVED with resolution FIXED, and Mozilla indicated it could be closed unless further discussion was needed.

Model: gpt-5.4-nano Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:55 UTC Confidence: 0.90 8 comments
Chronology
  1. Sectigo discovered an affected federal credit union certificate with an improper JOIStateName and scheduled it for revocation while beginning a search for additional cases.
  2. Sectigo’s query identified additional affected certificates for revocation.
  3. The initially discovered certificate was revoked.
  4. Additional discovered certificates were revoked.
  5. Sectigo’s QGIS matching functionality went into production.
  6. Sectigo filed this CA Program bug describing the issue and its remediation.
  7. Mozilla indicated the bug could be closed and scheduled closure unless more discussion was needed.
Thread Activity
  1. Sectigo — Sectigo described how it discovered eleven certificates with improper JOIStateName values for federal credit unions, provided a revocation timeline, and stated it programmatically blocked the misissuance and announced the release in Bug 1724476 comment 12.
  2. Community commenter — Ryan Sleevi questioned why Sectigo’s prior commitments did not prevent delayed reporting and why the issue evaded detection until now, citing other Sectigo incidents and validation-related concerns.
  3. Sectigo — Tim Callan explained the reporting delay as related to planned timing around a QGIS matching release, acknowledged misjudgment, and described how detection required identifying federal-level incorporation for the affected credit unions.
  4. Community commenter — Ryan Sleevi pressed for more explicit answers about why prior commitments failed to prevent repeat issues and challenged the adequacy of the described technical approach.
  5. Sectigo — Tim Callan discussed organizational/process factors behind decision-making scrutiny and listed improvements to Sectigo’s WebPKI Incident Response processes and tools.
  6. Sectigo — Martijn Katerbarg stated Sectigo would monitor the bug for any additional comments.
  7. Sectigo — Tim Callan asked whether it was time to close the bug.
  8. Mozilla representative — Mozilla’s Ben Wilson said the bug could be closed and scheduled closure on or about 17-Dec-2021 unless more discussion was needed.
Participants
Sectigo Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 100% similar
Sectigo: Incorrect OCSP responses
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 100% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1620561 RESOLVED Self Reported Incident Opened 2020-03-06 · Closed 2023-02-22 · 100% similar
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 100% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 100% similar
Sectigo: CPR response issues
#1715024 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-06-07 · Closed 2023-02-22 · 100% similar
Sectigo: Misspellings in stateOrProvince or localityName fields

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action