← Sectigo cases
Bugzilla #1895722
Certificate Misissuance
Sectigo: Incorrect inclusion of DBA name
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo issued two OV server certificates that incorrectly included both the Subscriber's legal name and their registered trade name in the subject:organizationName attribute, which is against TLS BRs. The certificates were revoked shortly after the issue was identified. A total of four certificates were found to be misissued, prompting an internal review and the implementation of a pre-issuance linter to prevent future occurrences. The incident was resolved with no further actions required.
Chronology
- Order received for OV server certificate
- Two identified certificates revoked
- Additional discovered certificates revoked
- Pre-issuance linter deployed
- Final action item completed
Participants
Martijn Katerbarg
Ben Wilson
External References
Similar Local Cases
Sectigo: SMIME issuance with insufficient validation of mailbox authorization or control
Sectigo: Missing data in cabfOrganizationIdentifier
Sectigo: Misspelled city name in localityName field
Sectigo: EV Certificate issuance with incorrect subject:serialNumber attribute value
Sectigo: Incorrect JOI for federal credit unions
Sectigo: Incorrect JOI Country value
Sectigo: Incorrect JOI
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates