Closed Bug 2032485 Opened 3 months ago Closed 3 months ago

DigiCert: Misissuance detected by PKIMetal

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED INVALID

People

(Reporter: incident-reporting, Assigned: dcbugzillaresponse)

References

(Blocks 1 open bug)

Details

(Whiteboard: [ca-compliance])

CA: Symantec (DigiCert)
Issue: Invalid domain name syntax

Examples:

crt.sh trust flags:

  • 360 Browser: No
  • Apple: No
  • Microsoft: Yes
  • Mozilla: No
  • Chrome: No
  • Android: No
  • Gmail: No
  • Java: Yes
  • Cisco: No
  • EUTL QWAC: No
  • Adobe EUTL: No
  • Adobe AATL: No
  • Adobe CDS: No
Assignee: nobody → dcbugzillaresponse
Status: NEW → ASSIGNED

Preliminary Incident Report

Summary

  • Incident description: A third-party reporter posted on Bugzilla that several leaf certificates issued by “Symantec Class 3 Secure Server CA - G4” were flagged as having invalid domain name syntax in a linter. “Symantec Class 3 Secure Server CA - G4” is not trusted in any CCADB Browser program root store. We request that this bug be closed as INVALID.
  • Relevant policies: Not applicable.
  • Source of incident disclosure: Third Party.

I can confirm this is invalid having already disclosed this, amongst other issues, to DigiCert last September (Case 04568136).

We request that this bug be closed as INVALID.

Whiteboard: [ca-compliance] [__-misissuance] [external] → [close as invalid on 2026-05-01] [ca-compliance]
Status: ASSIGNED → RESOLVED
Closed: 3 months ago
Resolution: --- → INVALID
Whiteboard: [close as invalid on 2026-05-01] [ca-compliance] → [ca-compliance]
You need to log in before you can comment on or make changes to this bug.