← DigiCert cases
Bugzilla #1896462 Certificate Problem Report

Digicert: Preview certificate uploaded to CCADB instead of the actual certificate

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert reported that, during testing of its CCADB API upload function, a “preview” subordinate CA certificate from a staging environment was uploaded to CCADB instead of the publicly trusted certificate. The preview certificate was described as identical to the final certificate except that it was not signed by a trusted root and had a different serial number. DigiCert stated that it later uploaded and revoked the trusted ICA after realizing the error, and that the affected ICA was not used to issue any end-entity certificates and was not in production at the time. Mozilla’s Ben Wilson noted that the issue caused DigiCert to miss a 7-day reporting deadline for the true subordinate CA to CCADB, and that the revoked serial was the one that had been revoked while another serial had not been revoked because it was never signed by the DigiCert Assured ID Root G2. Sectigo’s Rob Stradling raised questions about whether CCADB verifies signatures on submission and provided evidence links to crt.sh. The bug was resolved as FIXED, and Mozilla stated it would remove the preview certificate from CCADB because it was not signed within a trusted-root hierarchy.

Model: gpt-5.4-nano Generated: 2026-06-13 11:44 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.50 8 comments
Chronology
  1. A publicly trusted ICA was signed, and a preview certificate was uploaded to CCADB from the staging environment instead of the trusted certificate.
  2. Digicert found the issue, uploaded the correct certificate to PrimaRoot production and CCADB, and revoked the certificate.
  3. Mozilla closed the bug and stated it would remove the preview certificate from CCADB.
Thread Activity
  1. DigiCert — Digicert described how a preview certificate from staging was uploaded to CCADB instead of the trusted certificate, explained the root cause, and stated they added signature checking and revoked/updated the affected ICA.
  2. Sectigo — Rob Stradling said he noticed the issue via crt.sh, asked whether CCADB verifies signatures on submission, and referenced crt.sh links for the trusted and preview certificates.
  3. Mozilla representative — Ben Wilson agreed Mozilla should investigate signature verification behavior and created Bug #1896487 for the Common CA Database component.
  4. Sectigo — Rob noted crt.sh CT log ingestion had fallen behind and might take a few days to catch up.
  5. Mozilla representative — Ben clarified that DigiCert missed a 7-day reporting deadline for the true subordinate CA, and that the preview serial had not been revoked because it was never signed by the DigiCert Assured ID Root G2.
  6. DigiCert — Jeremy asked what else was needed and said DigiCert added signature checking and revoked the ICA, requesting closure.
  7. Mozilla representative — Ben said he would close the bug the following week to allow questions.
  8. Mozilla representative — Ben stated he was closing the bug and would remove the preview certificate from CCADB because it was not signed within a trusted-root hierarchy.
Participants
DigiCert Sectigo Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1824206 RESOLVED Certificate Problem Report Opened 2023-03-23 · Closed 2023-04-07 · 62% similar
DigiCert: Inconsistent validation information
#1664325 RESOLVED Ca Certificate Compliance Opened 2020-09-10 · Closed 2023-02-22 · 61% similar
DigiCert: SHA-256 hash algorithm used with ECC P-384 key
#2013375 RESOLVED Ca Documents Common Ca Database Opened 2026-01-29 · Closed 2026-02-18 · 61% similar
DigiCert: Issues with CCADB entries
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 61% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1586604 RESOLVED Certificate Misissuance Validation Issue Opened 2019-10-06 · Closed 2022-11-14 · 60% similar
DigiCert: TERENA: No localityName in EV precert
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 60% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName
#1427034 RESOLVED Ca Security Vulnerability Security Incident Opened 2017-12-25 · Closed 2024-05-09 · 53% similar
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
#1518555 RESOLVED Certificate Misissuance Opened 2019-01-08 · Closed 2023-02-22 · 52% similar
DigiCert: Use of forbidden subjectPublicKeyInfo algorithm

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action