← Sectigo cases
Bugzilla #1902748
Certificate Problem Report
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo identified a misissuance of QWAC certificates due to incorrect values in the subject:organizationIdentifier attribute. The issue arose from allowing customers to input organization identifiers during the order process, which led to validation errors. A total of three certificates were affected, and revocation actions were taken promptly. Improvements to the validation process have been implemented to prevent future occurrences.
Chronology
- Initial investigation confirms misissued certificate.
- First reported certificate revoked.
- Two additional certificates revoked.
- Final action item completed.
Participants
Martijn Katerbarg
Tim Callan
Ben Wilson
External References
Similar Local Cases
Sectigo: Mojibake in certificate Subject fields
Sectigo: Missing character in subject:organizationName attribute value
Sectigo: Lack of input validation in stateOrProvinceName
Sectigo: Misspellings in stateOrProvince or localityName fields
Sectigo: "Manual DCV" method used
Sectigo: S/MIME certificates with (null) string value in subject attributes
Sectigo: SC45 DCV Reuse Error
Sectigo: HTML encoded characters in subject attribute values