Sectigo disclosed non-existent hostname in CDP and AIA URLs for newly issued subordinate CA certificates
Sectigo reported that it discovered a problem while working on a crt.sh feature that tracks CCADB CRL disclosures, when Rob Stradling noticed one of its CRLs had a hostname that did not exist. The bug describes newly issued subordinate CA certificates whose OCSP, CRL, and caIssuer hostnames had not been created in DNS. Sectigo said it disabled the subordinate CAs until the certificates were disclosed in CCADB, then re-enabled them and later added the required DNS CNAME records. Sectigo stated that no further certificates were issued between discovering and fixing the root cause, and that two certificates issued on 2022-09-21 were affected. Sectigo later said remediation was complete and asked whether the bug could be closed; Mozilla indicated it would close the bug unless there were further questions.
- Sectigo issued new subordinate CA certificates and initially disabled them until CCADB disclosure was possible.
- Sectigo issued two leaf certificates under the new subordinate CA certificates with non-existent caIssuer, OCSP, and CRL hostnames.
- Sectigo added the required DNS CNAME records for the missing hostnames.
- Sectigo said remediation of the incident was complete.
- Sectigo — Sectigo opened the bug and explained that it had discovered the non-existent hostname issue while working on a crt.sh feature.
- Sectigo — Sectigo said the remediation steps were complete and it was monitoring the bug for comments.
- Sectigo — Sectigo asked whether the bug could be closed.
- Mozilla representative — Mozilla said it would close the bug on or about 2022-10-21 unless there were additional questions or issues.