DigiCert: Incorrect Org ID Scheme in S/MIME certificates (self-audit)
DigiCert opened this bug as a preliminary report after its self-auditing identified an issue in the organizationIdentifier field for some S/MIME certificates. The problem was that the NTR scheme was used while “government entity” was incorrectly listed, affecting 89 S/MIME certificates across 2 customers. DigiCert stated it would revoke the affected certificates within the 5-day period specified in the S/MIME Baseline Requirements, and that the values for the two accounts were corrected so customers could reissue end-entity certificates. DigiCert also implemented a block to prevent the invalid combination from being entered for new accounts and restarted account validation after the patch was deployed. In the follow-up report, DigiCert provided a timeline including ceasing validation of new accounts, rolling out the patch, and revoking the 89 certificates. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it would close the case after confirming action items were complete.
- DigiCert self-audit team identified a suspected bad organizationIdentifier value for some S/MIME certificates and escalated it for investigation.
- DigiCert confirmed the issue with stakeholders and triggered a request to pull the affected certificate population.
- DigiCert ceased validation of new accounts until a fix could be deployed.
- DigiCert corrected details for the two affected customers and rolled out a patch blocking the invalid NTR registration number combination; validation restarted.
- DigiCert revoked the 89 affected S/MIME certificates.
- Community commenter — DigiCert reported that its self-audit found an incorrect organizationIdentifier scheme/value for some S/MIME certificates, impacting 89 certificates across 2 customers, and stated affected certificates would be revoked within 5 days while a patch and validation block were implemented.
- Community commenter — DigiCert posted steps to reproduce, impact, a detailed timeline, and root cause analysis describing how the wrong scheme/value combination was entered, along with action items and outcomes (revocation and patch).
- Community commenter — DigiCert stated it was monitoring for any questions.
- Community commenter — DigiCert asked whether the bug could be closed since action items were complete.
- Mozilla representative — Mozilla stated it would close the bug sometime next week (June 17–21).