logo

DigiCert mass-revoking TLS certificates due to domain validation bug

ID: b242c682-5d09-510d-a4ca-646afde2b62b

STIX ID: report--b242c682-5d09-510d-a4ca-646afde2b62b

Feed Name: Bleeping Computer

Threat Score
30/100

Date Published: 2024-07-30

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

**Executive summary:** DigiCert discovered a five-year bug in its Domain Control Verification process that omitted the required underscore in some CNAME-based validations, impacting about 0.4% of validations (83,267 certificates, 6,807 customers). Under CABF rules DigiCert will revoke affected certificates within 24 hours and requires customers to reissue certificates via CertCentral to avoid connectivity loss; the company says the chance of a collision is extremely low and no exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.