DigiCert: S/MIME certificates issued inconsistent with Mozilla S/MIME BRs
DigiCert reported that it became aware on 6 September 2023 of a small number of S/MIME certificates that were issued in breach of the recent S/MIME BRs. DigiCert stated that its compliance/internal audit team ran PKILINT over S/MIME certificates issued since 1 September and found anomalies, which were sent to the relevant teams for investigation and remediation. DigiCert provided a timeline showing multiple corrective actions, including updating CertCentral OID profiles, patching DigiCert PKI platform issues, revoking affected certificates as they were identified, and finalizing and revoking the final certificates by mid-September. DigiCert also described causes across different platforms, including workflow/profile handling issues and a timing window when SMIME BR changes were enabled, as well as a revocation-date synchronization problem that could overwrite dates. DigiCert confirmed in a later comment that no new misissuance had occurred and that remediations were in place, and the bug was resolved as FIXED.
- DigiCert detected anomalies indicating a small number of S/MIME certificates were issued in breach of the S/MIME BRs.
- DigiCert provided a detailed response including a timeline, explanations, and a CSV of affected certificates.
- DigiCert confirmed no new misissuance and that remediations were in place.
- Community commenter — DigiCert stated it became aware on 6 September of S/MIME certificates issued in breach of the S/MIME BRs, estimated fewer than 40 impacted, and said affected certificates were being revoked as found.
- Community commenter — DigiCert provided answers including how it discovered the issue, a detailed timeline of actions, explanations of causes, and referenced attached CSV data for problematic certificates.
- Community commenter — An attachment (SMIME.csv) was created with the certificate data for the problematic certificates.
- Community commenter — DigiCert confirmed no new misissuance had occurred and that all remediations were in place, and asked if the bug could be closed.