← DigiCert cases
Bugzilla #1910322 · Certificate Problem Report
DigiCert: Random value in CNAME without underscore prefix
DigiCert · CLOSED
AI Summary
DigiCert identified a significant issue where approximately 83,267 certificates were issued using a random value in a CNAME record without the required underscore prefix. This oversight was discovered during an internal review prompted by a certificate problem report. The company has since taken steps to revoke all affected certificates and has implemented changes to ensure compliance with the CA/Browser Forum's Baseline Requirements. The incident highlights the importance of rigorous validation processes in certificate issuance.
Chronology
- Initial report of potential mis-issuance received.
- DigiCert completed revocation of all affected certificates.
- Closure summary posted detailing incident and remediation steps.
Participants
Jeremy Rowley
Tim Hollebeek
Ben Wilson
External References
Similar Local Cases
DigiCert: Truncation of Registration Number
DigiCert: Certificate Issues Identified on the Mailing List
Digicert: Government Entity listed instead of registration number
Digicert: SMIME certificate with unvalidated information
DigiCert: OCSP responder returning invalid responses
DigiCert: BR 3.2.5 Validation of Authority Failure for OV Certs
DigiCert: Late incident report for bug 1925106
DigiCert: Encoded HTML entities in attribute values