Sectigo: Missing data in cabfOrganizationIdentifier
Sectigo reported an incident involving misissued QWAC certificates where the cabfOrganizationIdentifier extension was missing part of the Registration Reference when a dash was included in the subject:organizationIdentifier value. The issue was triggered after Sectigo received a private social-media message recommending an investigation of 19 certificate serial numbers; further research identified 5 misissued certificates in total. Sectigo stated that it halted issuance of all QWAC-based certificates during the investigation and patch development. A patch was developed, released to QA, and deployed to the issuance system, after which Sectigo resumed QWAC-based certificate issuance and allowed replacement certificates to be issued. Sectigo scheduled revocation of the affected certificates for September 3, 2024, and reported that the affected certificates were revoked. The bug was later marked as resolved/fixed, with Sectigo stating that all incident response action items were completed and requesting closure.
- Sectigo began investigating 19 QWAC certificate serial numbers after receiving a social-media message.
- Sectigo identified that cabfOrganizationIdentifier was missing part of the Registration Reference when a dash was present and scoped the issue.
- Sectigo deployed an urgent patch to its issuance system during a planned outage window.
- Sectigo resumed QWAC-based certificate issuance to allow replacement certificates to be issued.
- Sectigo revoked the affected certificates.
- Sectigo requested closure after completing incident response action items.
- Sectigo — Provided a preliminary incident report stating that 5 misissued certificates were found, a patch was being developed, revocation was scheduled for 2024-09-03, and a full incident report would follow by 2024-09-06.
- Sectigo — Posted the full incident report describing the impact (5 certificates issued between 2023-12-28 and 2024-08-13), the timeline (including halting issuance and deploying a patch), the root cause analysis, and lessons learned.
- Sectigo — Stated that incident response action items were completed and that the team would monitor for questions/comments.
- Mozilla representative — Indicated Mozilla would close the bug on or about 2024-09-25 unless additional questions/comments were raised.