Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
This case reports a certificate misissuance by Sectigo involving QWAC certificates that were issued with incorrect subject:organizationIdentifier attribute values. The issue was triggered after a suspected misissued certificate was reported in comment #19 of bug 1897548, and Sectigo’s initial investigation confirmed the certificate was misissued. Sectigo’s investigation found additional misissued certificates sharing the same root cause: customers were allowed to enter the organization identifier during the retail order process, and validation did not correct errors, leading to incorrect subject:organizationIdentifier values being included. Sectigo reported that 3 certificates were issued between 2024-04-23 and 2024-06-13, and it scheduled revocation for the affected certificates (including revocation of the first reported certificate within 5 days of being reported and revocation of two additional certificates on 2024-06-24). During continued management of the bug, Sectigo identified one additional affected certificate and scheduled its revocation for 2024-07-21. Sectigo later deployed changes to complete the final action item on August 24, 2024, stated there were no further actions pending, and requested closing the bug; Mozilla indicated it would close it on or about August 28, 2024.
- A suspected misissued QWAC certificate was reported, prompting Sectigo to begin review.
- Sectigo confirmed the certificate was misissued and started a revocation event.
- Revocation was scheduled for the initially identified misissued certificate.
- Sectigo revoked two additional misissued certificates identified during review.
- Sectigo scheduled revocation for an additional affected certificate discovered later.
- Sectigo deployed changes to complete the final action item.
- Sectigo — Sectigo opened a preliminary incident report, stating the suspected certificate was indeed misissued and committing to post a full incident report by June 27, 2024.
- Sectigo — Sectigo posted the incident report, describing the root cause (customer-entered organization identifier not corrected during validation), the impact window (3 certificates between 2024-04-23 and 2024-06-13), and revocation and remediation timeline.
- Sectigo — Tim asked for a next update on 2024-08-31 to match remaining action items.
- Sectigo — Sectigo reported one additional affected certificate discovered during continued investigation and stated revocation was scheduled for 2024-07-21 around 16:00 UTC.
- Sectigo — Sectigo stated that changes required to complete the final action item were deployed on August 24, 2024, and requested closing the bug.
- Mozilla representative — Mozilla said it would close the bug on or about August 28, 2024 unless there were additional comments or concerns.