← DigiCert cases
Bugzilla #1894560 · Certificate Misissuance
DigiCert: Incorrect case in Business Category
DigiCert · RESOLVED
AI Summary
DigiCert identified a misissuance issue regarding the 'businessCategory' field in some EV certificates, where incorrect casing was used for values such as 'Private organization' instead of 'Private Organization'. This discrepancy was discovered during an internal investigation prompted by a call from Sectigo. DigiCert confirmed that 10,926 certificates issued between September and December 2023 were affected and have initiated revocation procedures. The issue stemmed from a misunderstanding of case sensitivity in the EV guidelines, leading to a compliance breach.
Chronology
- DigiCert employee contacted by Sectigo about case sensitivity issues.
- Investigation launched; initial findings confirm misissued certificates.
- DigiCert confirms 10,926 certificates affected and plans for revocation.
- All affected certificates revoked.
Participants
Martin Sullivan
Wayne Dickson
Jeremy Rowley
Ryan Dickson
Bill Wilson
Adriano Santoni
External References
Similar Local Cases
Digicert: Failure to include CPS URI in 1 certificate
DigiCert: Org-JOI type mismatch
DigiCert / Symantec: EV JOI Issue
DigiCert / Inteso San Paulo: Double dot characters
DigiCert: SMIME certificates issued inconsistent with BR’s
DigiCert: Mis-Issuance Rekey certificates
DigiCert / Swiss Government: CommonName not in SANs
DigiCert: Domain validation skipped