← Sectigo cases
Bugzilla #1876775 Certificate Misissuance

Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified a misissuance of 4,137 S/MIME certificates due to incorrect validation records based on Legal Entity Identifier (LEI) data. An internal audit revealed that the validation process did not comply with the S/MIME Baseline Requirements, leading to the issuance of certificates for 12 legal entities with invalid records. Following the discovery, Sectigo promptly initiated a revocation process for the affected certificates, which was completed on January 26, 2024. The company has since implemented a new pre-issuance linter to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 20:56 UTC Confidence: 0.95
Chronology
  1. Internal review raises suspicion about LEI records.
  2. Request for a complete list of approved pre-validation records.
  3. Verification script discovers invalid pre-validation records.
  4. Revocation of affected certificates completed.
  5. New pre-issuance linter deployed.
Participants
Martijn Katerbarg B. Wilson
External References
Similar Local Cases
#1782356 RESOLVED Certificate Misissuance Opened 2022-07-30 · Closed 2023-02-22 · 61% similar
Sectigo: Misspelled city name in localityName field
#1747915 RESOLVED Certificate Misissuance Opened 2021-12-29 · Closed 2023-02-22 · 60% similar
Sectigo: Incorrect JOI Country value
#1793789 RESOLVED Certificate Misissuance Opened 2022-10-05 · Closed 2023-02-22 · 60% similar
Sectigo: Incorrect JOI
#1860299 RESOLVED Certificate Misissuance Opened 2023-10-20 · Closed 2023-12-02 · 60% similar
Sectigo: SMIME issuance with insufficient validation of mailbox authorization or control
#1891245 RESOLVED Certificate Misissuance Opened 2024-04-12 · Closed 2024-05-13 · 60% similar
Sectigo: EV Certificate issuance with incorrect subject:serialNumber attribute value
#1895722 RESOLVED Certificate Misissuance Opened 2024-05-08 · Closed 2024-06-05 · 59% similar
Sectigo: Incorrect inclusion of DBA name
#1915883 RESOLVED Certificate Misissuance Opened 2024-08-30 · Closed 2024-09-26 · 58% similar
Sectigo: Missing data in cabfOrganizationIdentifier
#1917405 RESOLVED Certificate Misissuance Opened 2024-09-07 · Closed 2024-10-11 · 58% similar
Sectigo: S/MIME OV Mis-issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action