Sectigo: Wrong usage of LEI records for the issuance of S/MIME Certificates
Sectigo reported an incident discovered through an internal pre-validation records audit involving the use of LEI records for S/MIME certificate validation. The audit found that, in some cases, the requirements in the S/MIME Baseline Requirements were not met, specifically that LEI validation details were not properly verified (including RegistrationStatus, EntityStatus, and ValidationSources). Sectigo stated the impact as 4,137 S/MIME certificates issued to 12 legal entities with incorrect validation records, and noted that 1,522 of those had already been revoked via customer requests. After confirming 12 pre-validation records as invalid, Sectigo initiated internal revocation for the affected certificates that had not yet been revoked, with revocation scheduled for January 26 and completed by 22:00 UTC. Sectigo also reported that it deployed a new pre-issuance linter in its issuance system to prevent recurrence, after QA testing and deployment. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it would close the bug unless further questions or comments were raised.
- Sectigo’s internal pre-validation records audit raised suspicion about LEI-based S/MIME validation records not meeting S/MIME Baseline Requirements.
- Sectigo completed revocation of all affected, not previously revoked S/MIME certificates by 22:00 UTC.
- Sectigo deployed a new pre-issuance linter to prevent recurrence of the LEI validation issue.
- Sectigo — Created the incident report attachment describing 4,137 affected S/MIME certificates, invalid pre-validation records, and planned revocation and remediation actions.
- Sectigo — Confirmed revocation of all affected and previously not yet revoked certificates was completed by 22:00 UTC on January 26.
- Sectigo — Reported the new pre-issuance linter code passed initial code review and was with QA.
- Sectigo — Reported minor linter code changes after QA feedback and that QA sign-off was pending.
- Sectigo — Reported QA testing passed and the new pre-issuance linter was deployed on February 18; requested closing the bug.
- Mozilla representative — Indicated Mozilla would close the bug on or about 26-Feb-2024 unless there were questions or comments for Sectigo.