Sectigo: Incorrect inclusion of DBA name
Sectigo reported that on May 3, 2024 it issued OV server certificates whose subject:organizationName included both the subscriber’s legal name and its registered trade name/DBA separated by “d/b/a”. Sectigo stated that while inclusion of either the legal name or a registered trade name/DBA is allowed per the TLS BRs, inclusion of both is not allowed, and that the affected certificates were misissued. Sectigo revoked the initially identified certificates on May 7, 2024, and later found two additional misissued OV server certificates, scheduling and performing their revocation on May 12, 2024. Sectigo opened this bug on May 8, 2024 after confirming the additional misissued certificates and stated that it had no further actions remaining. Sectigo also described corrective actions, including deploying a pre-issuance linter during a maintenance window from May 18 to May 19, 2024, expanding validation training with the case study, and completing a final action item by May 24, 2024. Mozilla asked whether the bug could be closed, and Sectigo confirmed there were no further actions and that it would continue monitoring for questions or comments.
- Sectigo issued two OV server certificates with both legal name and registered trade name/DBA in subject:organizationName separated by “d/b/a”.
- Sectigo revoked the initially identified misissued certificates.
- Sectigo confirmed two additional misissued certificates and opened this bug.
- Sectigo revoked the additional misissued certificates.
- Sectigo deployed a pre-issuance linter during a maintenance window to prevent issuance with “d/b/a” or “DBA” in subject:organizationName.
- Sectigo completed the final action item and concluded incident handling.
- Sectigo — Sectigo provided a preliminary incident report describing the May 3 misissuance, stating the two affected certificates were revoked on May 7, and noting investigation for any other similar certificates.
- Sectigo — Sectigo posted the full incident report, including that two additional misissued OV server certificates were found and describing the timeline, root cause analysis, and planned corrective actions.
- Sectigo — Sectigo reported that a maintenance window ran from May 18 23:00 UTC to May 19 00:59 UTC during which the pre-issuance linter was deployed, updating action items.
- Sectigo — Sectigo stated that the final action item was completed on May 24 and that incident handling was concluded.
- Mozilla representative — Mozilla asked whether the bug could be closed if no other actions remained.
- Sectigo — Sectigo confirmed there were no further actions and that it would keep monitoring for questions or comments.