← DigiCert cases
Bugzilla #1556948 · Certificate Misissuance
DigiCert: Validation Scope Incident
DigiCert · RESOLVED
AI Summary
DigiCert experienced a validation scope incident where certificates were improperly issued due to a flaw in a legacy feature called 'Certificates Plus'. This feature allowed for the addition of domains post-validation, leading to mis-issuance of certificates. Upon discovery, DigiCert promptly initiated an investigation, identified the root cause, and took corrective actions, including revoking affected certificates and disabling the faulty feature. The incident highlights the importance of rigorous validation processes and the need for continuous improvement in certificate issuance practices.
Chronology
- Support engineer noticed validation mismatch
- Root cause identified and faulty logic disabled
- 390 certificates reissued/revalidated; 679 revoked
- New domain validation system deployed
Participants
Jeremy Rowley
Ryan Sleevi
External References
Similar Local Cases
DigiCert: Domain validation skipped
DigiCert: Underscores - CVS Pharmacy
DigiCert: "Some-State" in stateOrProvinceName
DigiCert / Swiss Government: CommonName not in SANs
DigiCert / Siemens: Insufficient Serial Number Entropy
DigiCert / Telecom Italia: Several Problems
DigiCert: DigiCert issued cert with CN too long
DigiCert: in-addr.arpa Misissuance