Sectigo: Incorrect JOI for federal credit unions
Sectigo reported a compliance problem it discovered while researching its own corpus of certificates for possible misissuance. The CA found eleven certificates issued to U.S. federal credit unions that included jOIStateName fields containing local state names; Sectigo stated that for federal credit unions, JOIStateName is improper and should be omitted. Sectigo said it scheduled the initially discovered certificate for revocation on October 7, then queried for additional affected certificates and revoked the additional certificates after they were found. Sectigo also stated it programmatically blocked this form of misissuance and announced the release in Bug 1724476 comment 12. In response to discussion about delayed reporting, Sectigo explained that it initially planned to include the report with an upcoming QGIS matching release, but the release slipped multiple times due to COVID-19 absenteeism and scheduling decisions, and Sectigo acknowledged that it should have proceeded with reporting earlier. The bug is marked RESOLVED with resolution FIXED, and Mozilla indicated it could be closed unless further discussion was needed.
- Sectigo discovered an affected federal credit union certificate with an improper JOIStateName and scheduled it for revocation while beginning a search for additional cases.
- Sectigo’s query identified additional affected certificates for revocation.
- The initially discovered certificate was revoked.
- Additional discovered certificates were revoked.
- Sectigo’s QGIS matching functionality went into production.
- Sectigo filed this CA Program bug describing the issue and its remediation.
- Mozilla indicated the bug could be closed and scheduled closure unless more discussion was needed.
- Sectigo — Sectigo described how it discovered eleven certificates with improper JOIStateName values for federal credit unions, provided a revocation timeline, and stated it programmatically blocked the misissuance and announced the release in Bug 1724476 comment 12.
- Community commenter — Ryan Sleevi questioned why Sectigo’s prior commitments did not prevent delayed reporting and why the issue evaded detection until now, citing other Sectigo incidents and validation-related concerns.
- Sectigo — Tim Callan explained the reporting delay as related to planned timing around a QGIS matching release, acknowledged misjudgment, and described how detection required identifying federal-level incorporation for the affected credit unions.
- Community commenter — Ryan Sleevi pressed for more explicit answers about why prior commitments failed to prevent repeat issues and challenged the adequacy of the described technical approach.
- Sectigo — Tim Callan discussed organizational/process factors behind decision-making scrutiny and listed improvements to Sectigo’s WebPKI Incident Response processes and tools.
- Sectigo — Martijn Katerbarg stated Sectigo would monitor the bug for any additional comments.
- Sectigo — Tim Callan asked whether it was time to close the bug.
- Mozilla representative — Mozilla’s Ben Wilson said the bug could be closed and scheduled closure on or about 17-Dec-2021 unless more discussion was needed.