← Sectigo cases
Bugzilla #1860299 Certificate Misissuance

Sectigo: S/MIME certificate misissuance due to insufficient validation of mailbox authorization/control

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported that on October 18, 2023 it became aware of at least one S/MIME certificate that had been issued with insufficient validation of mailbox authorization or control. Sectigo investigated and released a patch the same day to remediate the issue, and it later posted an incident report describing the cause and scope. The incident report states that during development of updates to Sectigo’s internal certificate audit tooling for S/MIME, Sectigo discovered an S/MIME certificate issued more than 398 days after Domain Control Validation was completed. Sectigo reported that 114 S/MIME certificates were affected and deemed mis-issued, issued between 2023-09-01 and 2023-10-18, and it scheduled revocation, sent revocation notifications to affected subscribers, and revoked the initially discovered certificate and the additional affected certificates. Sectigo completed its incident report and indicated it had completed two open action items by November 15, and Mozilla closed the bug on December 1, 2023. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 18:58 UTC Confidence: 0.90 7 comments
Chronology
  1. Sectigo became aware of S/MIME certificates issued with insufficient validation of mailbox authorization/control and released a patch the same day.
  2. Sectigo deployed the patch to production and began investigating all issued certificates to identify affected certificates.
  3. Sectigo revoked the additional affected S/MIME certificates.
  4. Sectigo completed two open action items related to the incident report.
  5. Mozilla closed the bug after receiving the incident report updates.
Thread Activity
  1. Sectigo — Sectigo stated it became aware of at least one S/MIME certificate issued with insufficient mailbox authorization/control validation, investigated, released a patch the same day, and expected to post a full incident report by October 27, 2023.
  2. Mozilla representative — Mozilla provided a new incident report template link for Sectigo’s use.
  3. Sectigo — Sectigo created an attachment listing affected S/MIME mailbox control certificates.
  4. Sectigo — Sectigo posted the incident report describing discovery, impact (114 affected certificates), timeline, root cause analysis, and lessons learned.
  5. Sectigo — Sectigo asked Mozilla to set a next update date of 2023-11-30 to provide an update once two action items were completed.
  6. Sectigo — Sectigo stated both action items were completed on November 15 and requested closing the bug if there were no further comments or questions.
  7. Mozilla representative — Mozilla said it would close the bug on Friday, 1-Dec-2023.
Participants
Sectigo Mozilla representative
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 99% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1829746 RESOLVED Certificate Misissuance Opened 2023-04-24 · Closed 2023-06-02 · 99% similar
Sectigo: Certificate issuance delayed for more than 398 days after DCV was completed
#1853987 RESOLVED Certificate Misissuance Opened 2023-09-19 · Closed 2023-10-12 · 99% similar
Sectigo: S/MIME certificates with (null) string value in subject attributes
#1756847 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 97% similar
Sectigo: SC45 DCV Reuse Error
#1897538 RESOLVED Certificate Misissuance Opened 2024-05-17 · Closed 2026-06-10 · 96% similar
Sectigo: Incorrectly included registrationStateOrProvince in PSD-based cabfOrganizationIdentifier extension
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 89% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1712188 RESOLVED Certificate Misissuance Opened 2021-05-20 · Closed 2023-02-22 · 89% similar
Sectigo: test certificates issued from trusted CA
#1946927 RESOLVED Incident Certificate Misissuance Opened 2025-02-08 · Closed 2025-05-16 · 88% similar
Sectigo: Intermittent OCSP unauthorized responses for certificates older than 15 minutes

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action