DigiCert self-reported WHOIS/DCV validation reuse after deprecation deadline affected 1,834 certificates
DigiCert reported an internal compliance issue involving Domain Control Validation method 3.2.2.4.2, where WHOIS-based validation was still being reused after the CA/B Forum deprecation date of 2025-07-15. DigiCert said its internal review found that validations tied to an Authorization Domain Name reached through a CNAME alias were not blocked as intended, which allowed additional certificates to be issued after the deadline. The company stated that it corrected the issue, blocked the affected validations, and revoked all 1,834 affected certificates. The report also says issuance was not stopped because the fix was deployed quickly and the validation state was cleared to force re-validation. The thread then focused heavily on whether the BR text allowed CNAME-based Authorization Domain Name handling in this method, but DigiCert maintained that the bug itself was about the post-deprecation issuance and that the remaining action item was replacing the workflows with its open-source DCV library by 2025-09-30.
- WHOIS-based DCV method 3.2.2.4.2 reached its deprecation date.
- DigiCert identified that certificates could still be issued using reused WHOIS-based validation for alias domains after the deprecation date.
- DigiCert revoked all 1,834 affected certificates and filed the bug report.
- DigiCert stated it was on track to replace the workflows with its open-source DCV library by this date.
- DigiCert — DigiCert filed a preliminary incident report describing the WHOIS/DCV reuse issue, the affected 1,834 certificates, and that all had been revoked.
- DigiCert — DigiCert filed the full incident report and said it cleared validation state to prevent further reliance on the old WHOIS validations.
- DigiCert — DigiCert said it did not believe the certificates were misissued and said the complaint was based on a re-interpretation of the TLS BRs.
- Mozilla representative — Mozilla said the incident raised questions about ADN and CNAME-following and noted that section 3.2.2.4.2 did not appear to allow substitution via CNAME.
- DigiCert — DigiCert said the bug was about the 1,834 certificates issued after the deprecation date and asked that unrelated BR interpretation discussion move to the CA/B Forum.
- DigiCert — DigiCert said it was on track to replace the workflows with its open-source DCV library by 2025-09-30.