Sectigo: Failure to invalidate Email DCV Random Values after 30 days
Sectigo reported a compliance incident discovered through its ongoing code-review process: the Random Values used in its email-based domain control validation did not get invalidated after 30 days from creation. Sectigo stated it deployed a patch on February 1, 2024 to remediate the possibility that Random Values could be considered valid beyond the 30-day deadline, and it continued investigating whether any non-compliant certificate issuance occurred. In its incident report, Sectigo said 2,577 unexpired certificates issued between 2023-01-08 and 2024-02-01 were issued based on domain control validation that used a Random Value that should no longer have been considered valid. Sectigo also said it disabled reuse of the domain control validations associated with suspect certificates and scheduled a revocation event for February 7, 2024 at 14:00 UTC, after which it reported that all affected certificates had been revoked. After remediation, Sectigo noted that the remaining action item was expansion of its internal certificate audit process, including a check against Random Value age, and requested closing the bug once that final item was completed. Mozilla indicated it would close the bug on Wed 3-Apr-2024, and the bug is resolved as FIXED.
- Sectigo deployed a patch to ensure email-based DCV Random Values are not treated as valid beyond 30 days.
- Sectigo revoked all certificates identified as affected by the Random Value invalidation issue.
- Sectigo completed the final internal audit process action and requested closure of the bug.
- Sectigo — Sectigo reported that it discovered Random Values for email-based DCV were not invalidated after 30 days, deployed a patch at 03:00 UTC, and planned to post a full incident report by Feb 9, 2024.
- Sectigo — Sectigo posted the incident report stating 2,577 unexpired certificates were issued using a Random Value that should no longer have been valid, and described the timeline and revocation plan.
- Sectigo — Sectigo said remediation was completed and asked Mozilla to set a next update for March 31 to track the final internal audit process item.
- Sectigo — Sectigo stated the final action item (including a check against Random Value age) was completed in its internal audit process and requested closing the bug.
- Mozilla representative — Mozilla agreed to close the bug on Wed 3-Apr-2024.