DigiCert: Misissuance detected by PKIMetal
The bug was opened as a certificate problem report after a third-party reporter posted on Bugzilla that several leaf certificates issued by “Symantec Class 3 Secure Server CA - G4” were flagged by a linter as having invalid domain name syntax. The reporter’s examples were linked via crt.sh, and the thread includes crt.sh trust flags showing which programs marked the certificates. The DigiCert incident reporter stated that “Symantec Class 3 Secure Server CA - G4” is not trusted in any CCADB Browser program root store. DigiCert requested that the bug be closed as INVALID, noting that the incident disclosure source was third party. Another participant confirmed the report was invalid and said they had already disclosed it to DigiCert last September (Case 04568136). The DigiCert incident reporter again requested closure as INVALID, and the bug status is RESOLVED with resolution INVALID.
- A third-party report on Bugzilla alleged leaf certificates issued by “Symantec Class 3 Secure Server CA - G4” had invalid domain name syntax.
- DigiCert (via the incident reporting account) provided example crt.sh links and trust-flag details and requested the bug be closed as INVALID.
- A participant confirmed the issue was invalid and referenced prior disclosure to DigiCert (Case 04568136).
- DigiCert again requested closure as INVALID; the bug is marked RESOLVED with resolution INVALID.
- CCADB representative — Provided examples of certificates flagged for invalid domain name syntax and listed crt.sh trust flags.
- DigiCert — Submitted a preliminary incident report stating the disclosure source was third party and requested the bug be closed as INVALID.
- Community commenter — Confirmed the report is invalid and said they had already disclosed it to DigiCert last September (Case 04568136).
- DigiCert — Requested again that the bug be closed as INVALID.