← Sectigo cases
Bugzilla #1977253 Certificate Misissuance

Sectigo: OV reuse data applied for wrong organization

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported an incident in which, due to human error, it applied OV reuse data for the wrong organization to a single OV TLS certificate. The incident began when a validation agent entered an incorrect existing order ID while using an OV data-reuse mechanism, resulting in the certificate being issued with incorrect organization details. Sectigo said it halted issuance of certificates using the affected reuse method until further notice, and it issued a replacement certificate and revoked the affected certificate at the subscriber’s request. Sectigo also created action items for technical controls to prevent recurrence, including a visual side-by-side comparison with string-matching indicators and a technical control that prevents assigning an organization whose name differs by more than 10% (using Levenshtein distance). In later comments, Sectigo stated that the action items were completed and requested closure of the incident report. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 19:04 UTC Confidence: 0.86 10 comments
Chronology
  1. Sectigo issued one OV TLS certificate containing incorrect organization details due to human error during OV data reuse.
  2. Sectigo identified the incident and opened the Mozilla CA Program bug after internal compliance review.
  3. Sectigo issued a replacement certificate and revoked the affected certificate at the subscriber’s request.
  4. Sectigo reported completion of the disclosed remediation action items and requested report closure.
Thread Activity
  1. Sectigo — Filed a preliminary incident report stating that human error led to OV reuse data being applied to the wrong organization, and that Sectigo revoked the certificate, fixed the OV reuse data, and created a ticket for technical controls.
  2. Sectigo — Posted a full incident report attachment listing affected certificates.
  3. Sectigo — Provided a full incident report including the timeline, impact (one certificate), and description of the OV data-reuse mechanism and root cause.
  4. Google representative — Asked two questions about the new preventative control’s minimum string-matching percentage and how the threshold was determined.
  5. Sectigo — Answered that the threshold was set at 90% initially and described the analysis method used to choose it.
  6. Community commenter — Questioned whether Sectigo violated the 72-hour requirement for the preliminary incident report and asked whether a separate incident bug should be opened.
  7. Sectigo — Responded that Sectigo did not agree with the assessment, explaining how it interpreted “becoming aware” and reporting expectations.
  8. Sectigo — Reported that both pending action items were completed and requested closure, describing the remediation controls added.
  9. CCADB representative — Issued a final call for comments and stated the incident report would be closed approximately 2025-09-11.
Participants
Sectigo Google representative Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1782356 RESOLVED Certificate Misissuance Opened 2022-07-30 · Closed 2023-02-22 · 97% similar
Sectigo: Misspelled city name in localityName field
#1902748 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-06-14 · Closed 2026-06-10 · 96% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
#1891245 RESOLVED Certificate Misissuance Opened 2024-04-12 · Closed 2024-05-13 · 91% similar
Sectigo: EV Certificate issuance with incorrect subject:serialNumber attribute value
#1915883 RESOLVED Certificate Misissuance Opened 2024-08-30 · Closed 2024-09-26 · 91% similar
Sectigo: Missing data in cabfOrganizationIdentifier
#1895722 RESOLVED Certificate Misissuance Opened 2024-05-08 · Closed 2024-06-05 · 89% similar
Sectigo: Incorrect inclusion of DBA name
#1747915 RESOLVED Certificate Misissuance Opened 2021-12-29 · Closed 2023-02-22 · 88% similar
Sectigo: Incorrect JOI Country value
#1718579 RESOLVED Certificate Misissuance Opened 2021-06-29 · Closed 2023-02-22 · 87% similar
Sectigo: "Manual DCV" method used
#1732484 RESOLVED Certificate Misissuance Opened 2021-09-24 · Closed 2023-02-22 · 87% similar
Sectigo: Truncated registration numbers in EV certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action