← Sectigo cases
Bugzilla #1747915
Certificate Misissuance
Sectigo: Incorrect JOI Country value
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo identified a misissuance of a certificate due to an incorrect subject:jurisdictionCountryName value. The issue arose from a software error during the verification process for a certificate order. Following an external report, Sectigo conducted an internal investigation, confirmed the misissuance, and scheduled a revocation. The affected certificate was revoked on December 21, 2021, and a patch was applied to prevent future occurrences. The incident highlighted challenges with legacy validation systems inherited from the acquisition of Xolphin.
Chronology
- External report received regarding incorrect country code.
- Certificate revoked.
Participants
Martijn Katerbarg
External References
Similar Local Cases
Sectigo: EV Certificate issuance with incorrect subject:serialNumber attribute value
Sectigo: Misspelled city name in localityName field
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
Sectigo: Incorrect JOI
Sectigo: Incorrect inclusion of DBA name
Sectigo: Missing data in cabfOrganizationIdentifier
Sectigo: SMIME issuance with insufficient validation of mailbox authorization or control
Sectigo: S/MIME OV Mis-issuance