← DigiCert cases
Bugzilla #1881364 Ca Certificate Compliance

DigiCert: SMIME certificate issued with unvalidated information (missing SMIME BR OID)

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert reported that, on 20 February, its internal checks identified a single S/MIME certificate that had been issued with unvalidated information and was missing the SMIME BR OID. DigiCert stated that the certificate was revoked. The investigation attributed the issue to a disaster recovery (DR) system that activated during system patching; this DR system was running older code that predated the S/MIME BRs. DigiCert said the DR system issued only one certificate before operations resumed at the production site, and that firewall rules prevented external certificate requests from the DR endpoint. DigiCert reported remediation steps including version monitoring for production and DR instances and uptime checks on DR instances, and it stated that it fixed the issue on 20 February and added it to an automated DR sync. Mozilla participants asked for clarification on the DR update procedures and firewall behavior; DigiCert responded that the impacted DR system was the one mentioned in the bug, that DR code and production code are deployed at the same time with a deployment success test, and that databases are continuously synced. The bug was marked FIXED, and DigiCert indicated it was monitoring for further questions before Mozilla closed it on 29 March 2024.

Model: gpt-5.4-nano Generated: 2026-06-13 11:43 UTC Revised: 2026-06-16 19:14 UTC Confidence: 0.90 10 comments
Chronology
  1. A certificate was issued by the disaster recovery system during a period when older DR code was in use.
  2. DigiCert’s internal checks identified the non-compliant S/MIME certificate and DigiCert revoked it.
  3. DigiCert fixed the DR issue and added it to an automated DR sync.
  4. Version monitoring for production and DR instances was completed.
  5. Uptime checks on DR instances were completed.
  6. Mozilla closed the bug after no further questions were raised.
Thread Activity
  1. Community commenter — Martin Sullivan reported that DigiCert was made aware via internal checks of a single SMIME certificate issued with non-validated information and said it had been revoked while the investigation continued.
  2. Community commenter — Martin Sullivan provided a reproduction/timeline and root cause analysis describing DR activation with older code, and listed action items (version monitoring and DR uptime checks).
  3. Community commenter — Martin Sullivan asked whether Mozilla was okay to close the bug given remediation completion.
  4. HARICA — Dimitris Zacharopoulos requested additional incident-report details, including when the DR code was updated and questions about DR instance impact and sync/testing processes.
  5. DigiCert — Jeremy Rowley answered that the issue was fixed on Feb 20 and added to automated DR sync, clarified only one DR system was impacted, and described deployment/sync testing and firewall behavior.
  6. HARICA — Dimitris Zacharopoulos acknowledged the clarifications and stated he had no further questions.
  7. Community commenter — Martin Sullivan stated DigiCert was monitoring for any further questions.
  8. Community commenter — Martin Sullivan asked if the bug could be closed.
  9. Mozilla representative — Ben Wilson said he would close the bug on Friday, 29-Mar-2024, unless additional questions were raised.
Participants
Community commenter HARICA DigiCert Mozilla representative
External References
Similar Local Cases
#1875205 RESOLVED Ca Certificate Compliance Opened 2024-01-18 · Closed 2024-01-26 · 98% similar
Digicert: SMIME certs missing State in Org ID
#1714439 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-03 · Closed 2023-02-22 · 96% similar
DigiCert: Incorrect RegNumber-Org Type combination
#1865235 RESOLVED Ca Certificate Compliance Opened 2023-11-17 · Closed 2023-12-07 · 96% similar
DigiCert: Late background refreshment check
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 95% similar
DigiCert: Issuance of Cert with Compromised Key
#1794050 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2022-10-06 · Closed 2023-02-22 · 95% similar
DigiCert: Org information issue in new validation workflow
#1710444 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-05-10 · Closed 2023-02-22 · 89% similar
DigiCert: Invalid stateOrProvinceName
#1335132 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-01-30 · Closed 2023-02-22 · 87% similar
DigiCert: Verizon mis-issued test certificates
#1927506 RESOLVED Ca Certificate Compliance Opened 2024-10-28 · Closed 2025-01-24 · 86% similar
DigiCert: Incorrect OrgID in S/MIME certificates for one customer

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action