← Sectigo cases
Bugzilla #1891245
Certificate Misissuance
Sectigo: EV Certificate issuance with incorrect subject:serialNumber attribute value
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo identified a misissuance of an EV certificate due to an incorrect subject:serialNumber attribute value. The certificate, issued on April 11, 2024, included a registration number of a defunct legal entity instead of the correct one. A total of 166 certificates were affected, with 33 already revoked prior to the incident's discovery. Revocation of the misissued certificate is scheduled for April 16, 2024, and a full incident report is expected by April 19, 2024.
Chronology
- Received Certificate Problem Report regarding misissued certificate.
- Scheduled revocation of the affected certificate.
- Expected release of full incident report.
Participants
Martijn Katerbarg
Amir Aamidi
B Wilson
External References
Similar Local Cases
Sectigo: Incorrect inclusion of DBA name
Sectigo: Incorrect JOI Country value
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
Sectigo: Misspelled city name in localityName field
Sectigo: Missing data in cabfOrganizationIdentifier
Sectigo: SMIME issuance with insufficient validation of mailbox authorization or control
Sectigo: Incorrect JOI
Sectigo: S/MIME OV Mis-issuance