Digicert: SMIME certs missing State in Org ID
DigiCert reported a compliance issue discovered during its internal review of issued certificates: some SMIME certificate OrgIDs for US-based companies were missing the state identifier. The issue was triggered when an employee noticed a SMIME certificate without a state identifier in the JOI, leading to an internal investigation and clarification of whether the state was required as part of the OrgID. DigiCert determined the root cause was system-related: automation expected for OrgID was never implemented, and in some cases the validation team did not add the state part of the OrgID even though it is required for most US companies. DigiCert’s review found 240 SMIME certificates across 16 organizations with incorrect OrgIDs, and it revoked all impacted certificates. DigiCert also deployed code to automate the OrgID entry and to scan the existing certificate population to detect impacted certificates. The bug was resolved as FIXED, and Mozilla indicated it would be closed on 26-Jan-2024.
- DigiCert discovered a SMIME certificate missing a state identifier in the JOI during an internal audit review, starting an investigation.
- DigiCert deployed automation to enter OrgID state and completed scanning, then revoked the final impacted certificates.
- Community commenter — Martin Sullivan described the internal discovery, impact (240 SMIME certificates across 16 organizations), root cause (missing OrgID automation), remediation (OrgID tool and scanning), and that all impacted certificates were revoked.
- Community commenter — Martin Sullivan asked whether they were OK to close the bug after remediation and revocation.
- Mozilla representative — Ben Wilson stated he would close the bug on Friday, 26-Jan-2024.