Sectigo: S/MIME certificate misissuance due to insufficient validation of mailbox authorization/control
Sectigo reported that on October 18, 2023 it became aware of at least one S/MIME certificate that had been issued with insufficient validation of mailbox authorization or control. Sectigo investigated and released a patch the same day to remediate the issue, and it later posted an incident report describing the cause and scope. The incident report states that during development of updates to Sectigo’s internal certificate audit tooling for S/MIME, Sectigo discovered an S/MIME certificate issued more than 398 days after Domain Control Validation was completed. Sectigo reported that 114 S/MIME certificates were affected and deemed mis-issued, issued between 2023-09-01 and 2023-10-18, and it scheduled revocation, sent revocation notifications to affected subscribers, and revoked the initially discovered certificate and the additional affected certificates. Sectigo completed its incident report and indicated it had completed two open action items by November 15, and Mozilla closed the bug on December 1, 2023. The bug is marked RESOLVED with resolution FIXED.
- Sectigo became aware of S/MIME certificates issued with insufficient validation of mailbox authorization/control and released a patch the same day.
- Sectigo deployed the patch to production and began investigating all issued certificates to identify affected certificates.
- Sectigo revoked the additional affected S/MIME certificates.
- Sectigo completed two open action items related to the incident report.
- Mozilla closed the bug after receiving the incident report updates.
- Sectigo — Sectigo stated it became aware of at least one S/MIME certificate issued with insufficient mailbox authorization/control validation, investigated, released a patch the same day, and expected to post a full incident report by October 27, 2023.
- Mozilla representative — Mozilla provided a new incident report template link for Sectigo’s use.
- Sectigo — Sectigo created an attachment listing affected S/MIME mailbox control certificates.
- Sectigo — Sectigo posted the incident report describing discovery, impact (114 affected certificates), timeline, root cause analysis, and lessons learned.
- Sectigo — Sectigo asked Mozilla to set a next update date of 2023-11-30 to provide an update once two action items were completed.
- Sectigo — Sectigo stated both action items were completed on November 15 and requested closing the bug if there were no further comments or questions.
- Mozilla representative — Mozilla said it would close the bug on Friday, 1-Dec-2023.