logo

DigiCert gives unlucky folks 24 hours to replace doomed certificates after code blunder

ID: d8d2aca4-b26c-5f00-82ab-833abaffbf8e

STIX ID: report--d8d2aca4-b26c-5f00-82ab-833abaffbf8e

Feed Name: The Register (Security)

Threat Score
30/100

Date Published: 2024-07-31

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

DigiCert discovered a bug introduced during a modernization that stopped adding a required leading underscore to random CNAME challenge values used for DNS-based domain validation, making affected TLS certificates non-compliant with CABF rules; approximately 0.4% of validations are impacted, and DigiCert is revoking and reissuing the certificates with instructions for customers to revalidate and reinstall replacements within 24 hours.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.