← Sectigo cases
Bugzilla #1897538 Certificate Problem Report

Sectigo: Incorrectly included registrationStateOrProvince in PSD-based cabfOrganizationIdentifier extension

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified a misissuance involving two QWAC PSD2 TLS certificates, where one certificate incorrectly included a registrationStateOrProvince in the cabfOrganizationIdentifier extension. The issue arose from a bug in their code that incorporated the NCA value into the registrationStateOrProvince field. Sectigo has since halted the issuance of such certificates and is investigating the impact on other certificates. A patch was deployed to resolve the issue, and a complete incident report was promised by May 29, 2024.

Model: gpt-4o-mini Generated: 2026-06-13 20:56 UTC Confidence: 0.90
Chronology
  1. Received a call about potentially misissued certificates.
  2. Confirmed one additional misissued certificate.
  3. Initiated customer contact regarding the situation.
  4. Scheduled revocation event for both misissued certificates.
  5. Promised completion of the incident report.
Participants
Martijn Katerbarg Ryan Dickson Clint Wilson
External References
Similar Local Cases
#1878139 RESOLVED Certificate Problem Report Opened 2024-02-01 · Closed 2024-05-20 · 62% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#2000277 RESOLVED Certificate Problem Report Opened 2025-11-14 · Closed 2025-12-19 · 61% similar
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA
#1853987 RESOLVED Certificate Problem Report Opened 2023-09-19 · Closed 2023-10-12 · 60% similar
Sectigo: S/MIME certificates with (null) string value in subject attributes
#1796803 RESOLVED Certificate Problem Report Opened 2022-10-21 · Closed 2023-02-22 · 59% similar
Sectigo: Issuance of ECC leaf certificates with non-DER encoded keyUsage
#1813989 RESOLVED Certificate Problem Report Opened 2023-01-31 · Closed 2023-05-04 · 59% similar
Sectigo: Incomplete Subject organizationName
#1912225 RESOLVED Certificate Problem Report Opened 2024-08-08 · Closed 2024-09-26 · 59% similar
Sectigo: HTML encoded characters in subject attribute values
#1740493 RESOLVED Certificate Problem Report Opened 2021-11-10 · Closed 2023-02-22 · 58% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1756847 RESOLVED Certificate Problem Report Opened 2022-02-23 · Closed 2023-02-22 · 58% similar
Sectigo: SC45 DCV Reuse Error

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action