← DigiCert cases
Bugzilla #1875205 Ca Certificate Compliance

Digicert: SMIME certs missing State in Org ID

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert reported a compliance issue discovered during its internal review of issued certificates: some SMIME certificate OrgIDs for US-based companies were missing the state identifier. The issue was triggered when an employee noticed a SMIME certificate without a state identifier in the JOI, leading to an internal investigation and clarification of whether the state was required as part of the OrgID. DigiCert determined the root cause was system-related: automation expected for OrgID was never implemented, and in some cases the validation team did not add the state part of the OrgID even though it is required for most US companies. DigiCert’s review found 240 SMIME certificates across 16 organizations with incorrect OrgIDs, and it revoked all impacted certificates. DigiCert also deployed code to automate the OrgID entry and to scan the existing certificate population to detect impacted certificates. The bug was resolved as FIXED, and Mozilla indicated it would be closed on 26-Jan-2024.

Model: gpt-5.4-nano Generated: 2026-06-13 11:43 UTC Revised: 2026-06-16 19:14 UTC Confidence: 0.90 4 comments
Chronology
  1. DigiCert discovered a SMIME certificate missing a state identifier in the JOI during an internal audit review, starting an investigation.
  2. DigiCert deployed automation to enter OrgID state and completed scanning, then revoked the final impacted certificates.
Thread Activity
  1. Community commenter — Martin Sullivan described the internal discovery, impact (240 SMIME certificates across 16 organizations), root cause (missing OrgID automation), remediation (OrgID tool and scanning), and that all impacted certificates were revoked.
  2. Community commenter — Martin Sullivan asked whether they were OK to close the bug after remediation and revocation.
  3. Mozilla representative — Ben Wilson stated he would close the bug on Friday, 26-Jan-2024.
Participants
Community commenter Mozilla representative
External References
Similar Local Cases
#1881364 RESOLVED Ca Certificate Compliance Opened 2024-02-21 · Closed 2024-03-29 · 98% similar
Digicert: SMIME certificate with unvalidated information
#1865235 RESOLVED Ca Certificate Compliance Opened 2023-11-17 · Closed 2023-12-07 · 95% similar
DigiCert: Late background refreshment check
#1714439 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-03 · Closed 2023-02-22 · 90% similar
DigiCert: Incorrect RegNumber-Org Type combination
#1927506 RESOLVED Ca Certificate Compliance Opened 2024-10-28 · Closed 2025-01-24 · 90% similar
DigiCert: Incorrect OrgID in S/MIME certificates for one customer
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 89% similar
DigiCert: Issuance of Cert with Compromised Key
#1710444 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-05-10 · Closed 2023-02-22 · 89% similar
DigiCert: Invalid stateOrProvinceName
#1794050 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2022-10-06 · Closed 2023-02-22 · 89% similar
DigiCert: Org information issue in new validation workflow
#1937210 RESOLVED Ca Certificate Compliance Opened 2024-12-13 · Closed 2025-02-28 · 85% similar
DigiCert: Late incident report for bug 1925106

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action