Sectigo: SC45 DCV Reuse Error
Sectigo reported that, through continuous QA testing, it became aware of incorrect DCV reuse occurrences caused by a bug in new code implemented for SC45 compliance. The issue related to BR 3.2.2.4.18, where certificates issued on or after 2021-12-01 must not be issued for other FQDNs ending with all labels of the validated FQDN unless a separate validation is performed using an authorized method. Sectigo stated it deployed a code fix and identified 40 affected certificates, revoking them within 24 hours of identification. In its investigation, Sectigo described how its Sticky DCV mechanism could create records that did not fully enforce the new restrictions on HTTP DCV checks introduced by SC45. Sectigo also reported that it deleted 404 problematic Sticky DCV records to stop any possibility of further misissuance. The bug was marked RESOLVED with resolution FIXED, and Sectigo stated remediation was completed and it would monitor for questions or comments.
- Sectigo’s SC45-related BR 3.2.2.4.18 restriction period began for certificates issued on or after this date.
- Sectigo deployed a hotfix to resolve the DCV reuse bug affecting SC45 compliance.
- Sectigo ran a script to identify problematic Sticky DCV entries and deleted 404 problematic records.
- Sectigo completed its review and confirmed 40 misissued certificates.
- Sectigo revoked all 40 confirmed misissued certificates.
- Sectigo — Sectigo reported that QA testing found incorrect DCV reuse due to a bug in SC45 compliance code, stated a code fix was deployed, and said 40 affected certificates were revoked within 24 hours while investigation continued.
- Sectigo — Martijn Katerbarg provided a detailed timeline and explained how Sticky DCV could bypass new HTTP DCV restrictions, including steps taken (hotfix, identification, deletion of problematic records, and revocation of 40 certificates).
- Sectigo — Martijn Katerbarg stated remediation was completed, included necessary information, and said the bug would be monitored for questions or comments.
- Sectigo — Martijn Katerbarg requested closure of the bug due to no further questions or comments.
- Mozilla representative — Ben Wilson said he would take a look at closing the bug on Wed 23-Mar-2022 unless there were objections.