← DigiCert cases
Bugzilla #2032485 Ca Certificate Compliance Certificate Misissuance

DigiCert: Misissuance detected by PKIMetal

RESOLVED INVALID DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened as a certificate problem report after a third-party reporter posted on Bugzilla that several leaf certificates issued by “Symantec Class 3 Secure Server CA - G4” were flagged by a linter as having invalid domain name syntax. The reporter’s examples were linked via crt.sh, and the thread includes crt.sh trust flags showing which programs marked the certificates. The DigiCert incident reporter stated that “Symantec Class 3 Secure Server CA - G4” is not trusted in any CCADB Browser program root store. DigiCert requested that the bug be closed as INVALID, noting that the incident disclosure source was third party. Another participant confirmed the report was invalid and said they had already disclosed it to DigiCert last September (Case 04568136). The DigiCert incident reporter again requested closure as INVALID, and the bug status is RESOLVED with resolution INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 11:48 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.86 4 comments
Chronology
  1. A third-party report on Bugzilla alleged leaf certificates issued by “Symantec Class 3 Secure Server CA - G4” had invalid domain name syntax.
  2. DigiCert (via the incident reporting account) provided example crt.sh links and trust-flag details and requested the bug be closed as INVALID.
  3. A participant confirmed the issue was invalid and referenced prior disclosure to DigiCert (Case 04568136).
  4. DigiCert again requested closure as INVALID; the bug is marked RESOLVED with resolution INVALID.
Thread Activity
  1. CCADB representative — Provided examples of certificates flagged for invalid domain name syntax and listed crt.sh trust flags.
  2. DigiCert — Submitted a preliminary incident report stating the disclosure source was third party and requested the bug be closed as INVALID.
  3. Community commenter — Confirmed the report is invalid and said they had already disclosed it to DigiCert last September (Case 04568136).
  4. DigiCert — Requested again that the bug be closed as INVALID.
Participants
CCADB representative DigiCert Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 100% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities
#2007219 RESOLVED Ca Certificate Compliance Opened 2025-12-20 · Closed 2026-02-17 · 96% similar
DigiCert: Some certificates issued with CRLDPs that don’t exactly match CCADB disclosures
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 91% similar
DigiCert: Invalid localityName
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 88% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName
#1759122 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-11 · Closed 2022-11-14 · 88% similar
DigiCert: EV for Onion addresses without Tor Service Descriptor
#1586604 RESOLVED Certificate Misissuance Validation Issue Opened 2019-10-06 · Closed 2022-11-14 · 81% similar
DigiCert: TERENA: No localityName in EV precert
#1262610 RESOLVED Ca Certificate Compliance Opened 2016-04-06 · Closed 2023-02-22 · 81% similar
DigiCert: ECCE 001 issuing certificates without subject alternative name extension
#1664325 RESOLVED Ca Certificate Compliance Opened 2020-09-10 · Closed 2023-02-22 · 80% similar
DigiCert: SHA-256 hash algorithm used with ECC P-384 key

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action