Closed Bug 2054098 Opened 1 month ago Closed 1 day ago

Sectigo: Incorrect jurisdictionStateOrProvinceName attribute value in Code Signing certificate

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: martijn.katerbarg, Assigned: martijn.katerbarg)

Details

(Whiteboard: [ca-compliance] [cs-misissuance])

Attachments

(1 file)

Preliminary Incident Report

Summary

  • Incident description:

We received a support request stating an incorrect jurisdictionStateOrProvinceName value within a Code Signing certificate.

Sectigo is currently investigating the root cause of this incident.

  • Relevant policies: Baseline Requirements for the Issuance and Management of Publicly-Trusted Code Signing Certificates version 3.11.0 section 7.1.4.2.4 (c)

  • Source of incident disclosure: Third Party Reported

Assignee: nobody → martijn.katerbarg
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [cs-misissuance]

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000016

  • Incident description:

    We received a support request stating an incorrect jurisdictionStateOrProvinceName subject attribute value within a Code Signing certificate.

    Upon investigation it became clear that the certificate request was originally placed for an organization found to be in an “inactive” state. Our validation department then found the organization listed within a different state, and added the appropriate QGIS source and updated both the joiStateOrProvinceName and serialNumber subject attribute values.

    Shortly after, the Applicant replied the original registration had been updated to an “In Good Standing” state. Our validation department added the appropriate QGIS data verification source, but neglected to restore the joiStateOrProvinceName and serialNumber values, causing the mis issuance.

  • Timeline summary:

    • Non-compliance start date: 2026-07-06 – 19:28:28 UTC
    • Non-compliance identified date: 2026-07-10 – 07:49
    • Non-compliance end date: 2026-07-10 – 14:24:47
  • Relevant policies: Baseline Requirements for the Issuance and Management of Publicly-Trusted Code Signing Certificates version 3.11.0 section 7.1.4.2.4 (c)

  • Source of incident disclosure: Third Party Reported

Impact

  • Total number of certificates: 1
  • Total number of "remaining valid" certificates: 0
  • Affected certificate types: EV Code Signing
  • Incident heuristic: The full corpus of affected certificates are disclosed in the Appendix.
  • Was issuance stopped in response to this incident, and why or why not?: No. Automated issuance did not cause this incident. The issue lies within a single validation occurrence.
  • Analysis: N/A
  • Additional considerations: N/A

Timeline

All times in UTC.

2026-07-01:

  • 16:46:18 The affected certificate request is received.
  • 19:40 Our validation department starts processing the request.
  • 19:43 QIIS sources are added to the order to confirm the organization details and callback methods.
  • 19:59 We find a QGIS showing the organization as listed in the request. The organization is listed as “Pending Inactive”.
  • 20:07 We send an email to the Applicant raising the inactive organization listing, requesting confirmation or updated details. Against internal policy, the Applicant is not notified of this change.

2026-07-02:

  • 03:55 We add a new QGIS source to the document, verifying the same organization name, registered in Washington state. The joiStateOrProvinceName and serialNumber values are updated to reflect this state.
  • 06:57 The Applicant replies that the organization status has been rectified and is now marked as “Active and In Good Standing”.

2026-07-03:

  • 08:24 Based on the reply from the Applicant, organization details are confirmed and marked as completed. The order is pending a completed callback.

2026-07-06:

  • 12:37 All verification on the request is completed. The updated “joiStateOrProvinceName” value of “Washington” and serialNumber value goes unnoticed, leading to the misissuance.
  • 13:00 We send the hardware token to the Subscriber, containing the certificate and private key.

2026-07-09:

  • 20:33 Our reseller creates a support ticket on behalf of the Subscriber, confirming an incorrect “joiStateOrProvinceName” value was found within the certificate.

2026-07-10:

  • 07:49 The support ticket created the previous day is processed. The issue is escalated to a senior validation member. We start an investigation.
  • 13:54 Our compliance department is made aware of the incident.
  • 14:15 The incident is discussed during our standing weekly WebPKI Incident Response call.
  • 14:24:47 The certificate is revoked.
  • 14:59 This bug is opened.

Related Incidents

No related incidents involving the same Subject DN attributes were found within the last 2 years.

Root Cause Analysis

Contributing Factor #1: Unapproved Change

  • Description:
    The jurisdiction and serialnumber values were changed during the validation process without notifying or obtaining confirmation from the Applicant.

    Had this change been completed after a notification and approval by the Applicant, it is likely that this incident would not have occurred, given the Applicant’s notice post-issuance.

  • Timeline: 2026-07-01

  • Detection: This was detected at part of our incident investigation. Previous detection mechanisms, such as our internal sample audit, have not caught this in the past.

  • Interaction with other factors: N/A.

Contributing Factor #2: Validation against an unrelated entity

  • Description:
    No connection was established between the Washington registration and the Virginia registration, potentially causing the issuance of a certificate for one organization, to be provided to a different organization. The remainer of the validation process, including QIIS and callbacks, were performed against the correct organization.

  • Timeline: 2026-07-01 – 2026-07-06

  • Detection: This was detected at part of our incident investigation. Previous detection mechanisms, such as our internal sample audit, have not caught this in the past.

  • Interaction with other factors: N/A.

Contributing Factor #3: Failure to correct validation information

  • Description:
    Once the Applicant reached out confirming the organization was now in an Active state, we confirmed the details were correct and notified the customer, however the data was not appropriately updated within the certificate request itself.

  • Timeline: 2026-07-01 – 2026-07-06

  • Detection: This was detected at part of our incident investigation. Previous detection mechanisms, such as our internal sample audit, have not caught this in the past.

  • Interaction with other factors: N/A.

Had any single 1 of these 3 contributing factors not occurred, we believe the misissuance of this certificate would have been prevented.

Lessons Learned

  • What went well:
    • We were quickly able to revoke the certificate.
  • What didn’t go well:
    • Internal policy regarding updates to pending requests and accompanying notifications was not followed.
    • Certificate validation was performed after new evidence was received but the request was not updated to reflect this.
    • Automated notifications for changes to orders were not in place.
  • Where we got lucky: N/A
  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Investigate options of automated emails sent to Applicants in case of order changes. Prevent Contributing Factor #1 We are investigating what impact this would have on customers and staff. Pending positive results, we intend to implement automated notification emails warning applicants of any changes made to their request. 2026-08-31 Ongoing
Creation of additional warning within the validation system as guard rail, to aid in detecting a reoccurrence of this incident. These warnings will be triggered if the Jurisdiction of Incorporation (JOI) details differ from the registered address of the organization. Prevent Contributing Factor #2 Completely blocking different JOI values from registered details has been deemed not possible, due to how many organizations, at least in some countries, including the US, are incorporated in one state, but located in a different state. Examples of this are Delaware registered organizations. 2026-08-03 Ongoing
Creation of additional, automated, verification and warning within the validation system as guard rail, performing a lookup against a well-known QIIS. In case this automated lookup detects multiple organizations utilizing the same organization name within the same country, a warning will be shown to the validation agent to allow for additional scrutiny. Prevent Contributing Factor #2 and 3 During the initial few months, we intend on monitoring usage of this warning. We want to avoid “warning fatigue”, yet draw attention to any possible issues. 2026-08-03 Ongoing
Updating our standard operating procedure for validation combined with renewed training schemes. Prevent Contributing Factor #1 and 3 While we attempt to bring further guard rails, in some cases, the human error will always be a factor. As part of an already ongoing update to our operating procedures, additional training will be held with validation staff to put additional focus on allowed changes and how to handle these. 2026-08-03 Ongoing

Appendix

The affected certificate is listed in attachment #9615159 [details].

We're monitoring this bug for any questions and comments. Meanwhile we continue on our action items.

3 Out of 4 action items have been completed per the schedule above. We'd like to request a next-update for 2026-08-31 for the final action item.

Flags: needinfo?(bwilson)
Whiteboard: [ca-compliance] [cs-misissuance] → [ca-compliance] [cs-misissuance] Next update 2026-08-31
Flags: needinfo?(bwilson)

Our final action item has been completed.

Report Closure Summary

  • Incident description:
    A certificate request was placed for an organization found to be “inactive”. Our validation department found the organization listed within a different US-state, and added the appropriate QGIS source and updated both the joiStateOrProvinceName and serialNumber subject attribute values.

    Shortly after, the Applicant replied the original registration had been updated to an “In Good Standing” status. Our validation department added the appropriate QGIS data verification source, but neglected to restore the joiStateOrProvinceName and serialNumber values, causing a misissuance.

  • Incident Root Cause(s):
    The jurisdiction and serialnumber values were changed during the validation process without notifying or obtaining confirmation from the Applicant. This, combined with a lack of warnings based on automated lookups, led to this going undetected.

  • Remediation description:
    Automated lookups providing warnings have been added to the system in case multiple organizations have been found with the same company name. In addition, warnings are now presented when the joiST value does not match the stateOrProvinceName attribute.

  • Commitment summary:
    Sectigo is further expanding customer notifications and confirmation prior to issuance as an additional safeguard.

All Action Items disclosed in this report have been completed as described, and we request its closure.

Flags: needinfo?(bwilson)

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-09-02.

Flags: needinfo?(bwilson)
Whiteboard: [ca-compliance] [cs-misissuance] Next update 2026-08-31 → [close on 2026-09-02] [ca-compliance] [cs-misissuance]
Status: ASSIGNED → RESOLVED
Closed: 1 day ago
Resolution: --- → FIXED
Whiteboard: [close on 2026-09-02] [ca-compliance] [cs-misissuance] → [ca-compliance] [cs-misissuance]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: