← DigiCert cases
Bugzilla #1500621 · Certificate Misissuance
DigiCert: Internal Domain Name cert mis-issuance
DigiCert · RESOLVED
AI Summary
DigiCert experienced a mis-issuance of a certificate containing an internal domain name due to a gap in their domain pre-validation process. The issue was reported by a third party on October 16, 2018, leading to an investigation that revealed a validation agent's override of the domain's classification. The certificate was revoked on October 17, 2018, and DigiCert implemented fixes to prevent similar occurrences in the future.
Chronology
- Third party reported internal domain name on a certificate.
- Certificate revoked and pre-issuance checks improved.
Participants
Brenda Bernal
Wayne Thayer
Jeremy Rowley
External References
Similar Local Cases
DigiCert: "Some-State" in stateOrProvinceName
DigiCert: in-addr.arpa Misissuance
DigiCert: Domain validation skipped
DigiCert: Incorrectly issued EV Certificate
DigiCert: SHA-1 intermediate issued after 2016-01-01
DigiCert: Underscores - Intuit
DigiCert: Underscores - CVS Pharmacy
DigiCert: Org-JOI type mismatch