DigiCert: Inconsistent validation information
The bug describes an issue where DigiCert certificates contained validation information that was inconsistent with what was shown in DigiCert’s portal snapshot. A partner notified DigiCert that a certificate’s details were not as expected; DigiCert investigated and found that the certificate was issued with updated information, but the portal content view was not updated. DigiCert reported that a system bug caused previously updated certificate subject data to be displayed to agents, while the issued certificate used the updated information. DigiCert started population scans, patched systems, and created a list of certificates where certificate content differed from the snapshot, which was reviewed internally. DigiCert’s management team completed a final review, sent customer notifications, and revoked the affected certificates on 21 March 2023. The bug was resolved as FIXED, and DigiCert stated that the system now forces an update of the snapshot for every certificate and that this was added to QA testing for production pushes.
- A partner notified DigiCert of a certificate whose details were not as expected, triggering DigiCert’s investigation.
- DigiCert patched systems related to the portal/snapshot inconsistency.
- DigiCert revoked the affected certificates.
- Community commenter — Martin Sullivan created the bug and provided DigiCert’s incident timeline, explanation of the underlying system bug, and remediation steps.
- Mozilla representative — Mozilla asked whether the impact was limited to 77 certificates and whether any affected certificates were DV versus OV/EV.
- DigiCert — DigiCert responded that the impact was limited to organization name and address (OV/EV only) and was small due to narrow timing circumstances.
- Community commenter — The commenter requested that the problematic-certificate section include first/last issuance dates to indicate when the bug was introduced.
- DigiCert — DigiCert clarified that the list provided reflected currently valid certificates with the issue and stated the bug was introduced during Symantec integration, with consolidation of validation systems occurring in 2019.
- DigiCert — DigiCert asked whether there were any other questions and whether the bug could be closed.
- Mozilla representative — Mozilla agreed to close the bug and scheduled it for 7-Apr-2023 in case of community comments.