← Sectigo cases
Bugzilla #1793787
Certificate Problem Report
Sectigo: Non-existent hostname in CDP and AIA URLs
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo identified a problem where two Subordinate CA certificates issued on September 21, 2022, contained non-existent hostnames in their CRL and OCSP URLs. The issue was discovered during the implementation of a new feature for tracking CRL disclosures. Following the identification of the problem, Sectigo took immediate action to rectify the DNS records and confirmed that no further certificates were issued with the problematic URLs. The incident was resolved by October 12, 2022.
Chronology
- Two Subordinate CA certificates issued with non-existent hostnames.
- DNS CNAME records added to resolve the issue.
- Remediation of the incident completed.
- Bug closed after confirming no further questions.
Participants
Martijn Katerbarg
Ben Wilson
External References
Similar Local Cases
Sectigo: S/MIME certificates with (null) string value in subject attributes
Sectigo: HTML encoded characters in subject attribute values
Sectigo: Premature disabling of CRL generation for an inactive CA
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
Sectigo: Temporary unavailability for subset of CRLs
Sectigo: Missing character in subject:organizationName attribute value
Sectigo: Failure to revoke ECC certificates with non-DER encoded keyUsage within 5 days
Sectigo: Late revocation for incomplete Subject organizationName