← DigiCert cases
Bugzilla #1927506
Ca Certificate Compliance
DigiCert: Incorrect OrgID in S/MIME certificates for one customer
RESOLVED
FIXED
DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
DigiCert identified an issue involving incorrect organization identifiers in 70,204 S/MIME certificates for a customer, discovered during an internal audit. The problem arose from a validation oversight that allowed the issuance of certificates with an NTR identifier for a government entity. DigiCert took immediate action by revoking all impacted certificates within the required timeframe. The root cause was linked to a previous bug, and DigiCert has since implemented additional checks to prevent recurrence. The issue has been resolved, and all actions have been completed.
Chronology
- DigiCert confirmed the incident and scheduled revocation of affected certificates.
- All impacted certificates were revoked.
Thread Activity
- DigiCert — Reported the incident and outlined the steps to reproduce the issue.
- DigiCert — Indicated ongoing work on the full report.
- DigiCert — Requested closure of the bug as all actions were completed.
Participants
DigiCert
Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
DigiCert: Late incident report for bug 1925106
DigiCert: Issuance of Cert with Compromised Key
Digicert: SMIME certs missing State in Org ID
DigiCert: Unclear Disclosure of CAA Issuer Domain Names
DigiCert: Incorrect RegNumber-Org Type combination
DigiCert: Org information issue in new validation workflow
DigiCert: Late background refreshment check
DigiCert: Invalid stateOrProvinceName