← DigiCert cases
Bugzilla #1927506 · Certificate Problem Report
DigiCert: Incorrect OrgID in S/MIME certificates for one customer
DigiCert · RESOLVED
AI Summary
DigiCert identified an issue with 70,204 S/MIME certificates containing an incorrect organization identifier for a government entity. This problem arose from a previous bug fix that did not account for non-German certificates. The error was detected during an internal audit, leading to a swift revocation of the affected certificates. DigiCert has since implemented additional checks to prevent recurrence of this issue.
Chronology
- Patch rolled out to block invalid registration numbers.
- Incident confirmed and certificates scheduled for revocation.
- All impacted certificates revoked.
- Closure request submitted as all actions completed.
Participants
Tim Hollebeek
DigiCert Team
External References
Similar Local Cases
DigiCert: Encoded HTML entities in attribute values
DigiCert: Some CRLs were not updated for a few days
DigiCert: Typo in TLS Org Name
DigiCert: Random value in CNAME without underscore prefix
DigiCert: Domain used for CRLs and OCSP has expired
Digicert: SMIME certs missing State in Org ID
DigiCert: BR 3.2.5 Validation of Authority Failure for OV Certs
DigiCert: Incorrect CP listed in CCADB