Digicert: Preview certificate uploaded to CCADB instead of the actual certificate
DigiCert reported that, during testing of its CCADB API upload function, a “preview” subordinate CA certificate from a staging environment was uploaded to CCADB instead of the publicly trusted certificate. The preview certificate was described as identical to the final certificate except that it was not signed by a trusted root and had a different serial number. DigiCert stated that it later uploaded and revoked the trusted ICA after realizing the error, and that the affected ICA was not used to issue any end-entity certificates and was not in production at the time. Mozilla’s Ben Wilson noted that the issue caused DigiCert to miss a 7-day reporting deadline for the true subordinate CA to CCADB, and that the revoked serial was the one that had been revoked while another serial had not been revoked because it was never signed by the DigiCert Assured ID Root G2. Sectigo’s Rob Stradling raised questions about whether CCADB verifies signatures on submission and provided evidence links to crt.sh. The bug was resolved as FIXED, and Mozilla stated it would remove the preview certificate from CCADB because it was not signed within a trusted-root hierarchy.
- A publicly trusted ICA was signed, and a preview certificate was uploaded to CCADB from the staging environment instead of the trusted certificate.
- Digicert found the issue, uploaded the correct certificate to PrimaRoot production and CCADB, and revoked the certificate.
- Mozilla closed the bug and stated it would remove the preview certificate from CCADB.
- DigiCert — Digicert described how a preview certificate from staging was uploaded to CCADB instead of the trusted certificate, explained the root cause, and stated they added signature checking and revoked/updated the affected ICA.
- Sectigo — Rob Stradling said he noticed the issue via crt.sh, asked whether CCADB verifies signatures on submission, and referenced crt.sh links for the trusted and preview certificates.
- Mozilla representative — Ben Wilson agreed Mozilla should investigate signature verification behavior and created Bug #1896487 for the Common CA Database component.
- Sectigo — Rob noted crt.sh CT log ingestion had fallen behind and might take a few days to catch up.
- Mozilla representative — Ben clarified that DigiCert missed a 7-day reporting deadline for the true subordinate CA, and that the preview serial had not been revoked because it was never signed by the DigiCert Assured ID Root G2.
- DigiCert — Jeremy asked what else was needed and said DigiCert added signature checking and revoked the ICA, requesting closure.
- Mozilla representative — Ben said he would close the bug the following week to allow questions.
- Mozilla representative — Ben stated he was closing the bug and would remove the preview certificate from CCADB because it was not signed within a trusted-root hierarchy.