DigiCert: Org/DBA information validation issue in new validation workflow (misissued certificates)
On September 29, 2022, DigiCert’s validation team detected an anomaly in an issued certificate where the “Name: [org name]” appeared in the O field. DigiCert staff investigated and determined the root cause of the mis-issued certificate was related to a UI issue in the new validation workflow that allowed validation staff to select more than the company name. On September 30, 2022, DigiCert detected another issued certificate containing a DBA that was not approved for inclusion, and DigiCert fixed the proxy behavior so a DBA would not be included unless it was validated and approved. DigiCert later found that cached validation information remained intact, which allowed additional certificates to be issued with non-verified DBA information; DigiCert remediated by clearing cached results and also clearing the high-volume certificate cache. DigiCert revoked all impacted certificates and updated the UX, added UI highlighting for mismatches, and added a unit test to check that OV certificates do not pass a DBA to the CA. The bug was marked RESOLVED with resolution FIXED, and DigiCert indicated it had initiated the revocation process for the impacted certificates and monitored for additional anomalies.
- DigiCert’s validation team detected an anomaly in an issued certificate involving unexpected organization name content in the O field.
- DigiCert detected another issued certificate with an unapproved DBA and fixed the validation proxy behavior.
- DigiCert cleared cached validation results to stop further issuance with non-verified DBA information.
- DigiCert completed a sweep to determine the final list of impacted certificates and initiated revocation for them.
- DigiCert cleared the high-volume certificate cache and continued revocation for additional impacted certificates.
- DigiCert — Created the incident report describing DigiCert’s detection of mis-issued certificates tied to the new validation workflow, the fixes applied, and the revocation process.
- DigiCert — Reported that DigiCert revoked all impacted certificates, updated the UX with additional highlighting, and added a unit test for OV certificates not passing a DBA.
- Mozilla representative — Indicated Mozilla would check back and close the bug unless additional questions were raised.
- Sectigo — Asked questions about the timeline precision, accounting for 13 precertificates, and whether revocation met the 5-day requirement.
- DigiCert — Answered the questions, provided a revised timeline with more precise timestamps, clarified that no mis-issuance occurred on Oct 4–5, and referenced related revocation delay in Bug 1797165.
- DigiCert — Stated there were no further updates.
- Mozilla representative — Planned to close the bug on or about Wed. 2-Nov-2022 unless further discussion was needed.