Disig: Certificates with invalid embedded SCT signature
Disig, a CA, discovered that four end-user OV certificates contained an invalid embedded Signed Certificate Timestamp (SCT) signature. Following this internal investigation, all affected certificates were revoked. A full incident report was initiated, detailing the root cause as a failure to preserve CT log response data during certificate assembly. Disig has implemented corrective actions, including the removal of the problematic CT log server from their active submission list and the integration of a new linter into their pre-issuance pipeline to prevent future occurrences. The incident is now resolved with all action items completed.
- Disig identified invalid SCT signatures in four OV certificates and revoked them.
- Disig, a.s. — Preliminary Incident Report submitted detailing the invalid SCT signatures.
- Disig, a.s. — Full Incident Report provided with a timeline and root cause analysis.
- Disig, a.s. — Report Closure Summary submitted, confirming all action items have been completed.