← Sectigo cases
Bugzilla #1860299
Certificate Misissuance
Sectigo: SMIME issuance with insufficient validation of mailbox authorization or control
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo identified a misissuance of 114 S/MIME certificates due to insufficient validation of mailbox authorization. The issue was discovered on October 18, 2023, leading to a swift investigation and the release of a patch the same day. Affected certificates were issued between September 1 and October 18, 2023. The root cause was linked to a design oversight in the E-PKI platform's validation mechanism, which failed to invalidate records after a certain period. Sectigo has since completed all action items related to this incident.
Chronology
- Discovery of misissued certificates and immediate patch development.
- Deployment of patch to production and revocation of affected certificates.
- Completion of all action items related to the incident.
Participants
Martijn Katerbarg
Ben Wilson
External References
Similar Local Cases
Sectigo: Missing data in cabfOrganizationIdentifier
Sectigo: Incorrect inclusion of DBA name
Sectigo: Misspelled city name in localityName field
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
Sectigo: Incorrect JOI for federal credit unions
Sectigo: Failure to revoke within 5 days
Sectigo: Incorrect JOI Country value
Sectigo: Incorrect JOI