DigiCert: TLS certificates with incorrect policy OID
DigiCert reported a self-discovered issue where some IV TLS certificates were issued with the IV CABF policy OID plus a DBA, and the DBA was determined to be an organization name. DigiCert stated that the problem was triggered when an employee noticed the affected certificates while adding SC-62 changes to an internal linter on July 19, 2023, and compliance reviewed the certificates on July 20. DigiCert said the certificates should have been marked as OV rather than IV, and that a system bug caused an entity marked as an individual to remain marked as an individual even after the status was changed to an organization. DigiCert patched the system to stop further incorrect labeling and refreshed the snapshot, then manually scanned the complete IV certificate population to identify impacted certificates. DigiCert finalized the impacted list, sent it to the revocation team, and scheduled certificates for revocation on July 30, with some revocations delayed for one customer (tracked in a follow-up bug). DigiCert later stated that all certificates were revoked and remediation was complete, and Mozilla indicated it would close the bug unless additional questions remained.
- DigiCert employee noticed some IV TLS certificates had the IV CABF policy OID plus a DBA while updating an internal linter.
- DigiCert compliance determined the DBA was an organization name and the certificates should have been marked as OV rather than IV; DigiCert patched the system and began remediation steps.
- Certificates were scheduled for revocation.
- DigiCert reported that all certificates were revoked and remediation was complete.
- Community commenter — Provided a detailed self-disclosure describing how DigiCert discovered the issue, the timeline, the cause (entity type flag not updating), and remediation steps including patching and revocation scheduling.
- Community commenter — Linked to bug 1846784 for tracking a delay in revocation for one customer.
- Community commenter — Updated bug 1846784 with the current revocation tracking status.
- Community commenter — Updated bug 1845634 with the current status.
- Community commenter — Reported that all certificates are now revoked and remediation is complete, and asked whether the bug could be closed.
- Mozilla representative — Said Mozilla would close the bug on or about Friday 1-Sept-2023 unless there were additional questions or issues.