Sectigo: EV certificate misissuance due to incorrect subject:serialNumber value
Sectigo reported an EV certificate misissuance after receiving a Certificate Problem Report (CPR) about the validity of the subject:serialNumber attribute value for a specific TLS certificate. Sectigo determined that, although the legal entity and organization details were valid, an incorrect subject:serialNumber value was validated and included in the certificate. The incorrect value was the registration number of a legal entity that was no longer incorporated but shared the same name as the legal entity the certificate was issued to; the value “09003091” should have been “30046259”. Sectigo stated that the incident affected 166 unexpired certificates issued between 2023-04-24 and 2024-01-11, and that 33 of these had already been revoked by the Subscriber prior to discovery. Sectigo scheduled revocation of the affected certificate for April 16, 2024 around 18:00 UTC and notified both the Subscriber and the CPR filer. Sectigo later said its incident report completed the actions related to the incident and that it was monitoring the bug for further comments; the bug was resolved with resolution “FIXED.”
- Sectigo received a CPR for a specific EV TLS certificate and determined the certificate was misissued.
- Sectigo scheduled revocation of the affected certificate for around 18:00 UTC.
- Sectigo published a full incident report describing the incorrect subject:serialNumber value and the incident impact.
- Sectigo stated its incident report completed actions and it would monitor the bug for questions.
- Mozilla indicated it would close the bug on or about May 13, 2024.
- Sectigo — Sectigo provided a preliminary incident report stating it received a CPR, determined the certificate was misissued, scheduled revocation for April 16, 2024, and expected a full incident report by April 19, 2024.
- Sectigo — Sectigo posted an incident report concluding the wrong subject:serialNumber value (“09003091” instead of “30046259”) was validated and included, and described the impact across 166 unexpired certificates.
- Sectigo — Sectigo said the incident report completed its actions related to the incident and that it was monitoring the bug for comments or questions.
- Community commenter — A participant asked how Sectigo accomplished the automation in this space.
- Sectigo — Sectigo replied that it used APIs from the Dutch Chamber of Commerce and mapped automated search results to fields verified by vetting agents.
- Sectigo — Sectigo noted comments appeared addressed and requested the bug be marked resolved unless new comments arrived.
- Mozilla representative — Mozilla stated it would close the bug on or about Monday, 13-May-2024.