From:  Jeremy Rowley <jeremy.rowley@digicert.com>
Date:  05 Jun 2019 22:51:59 Hong Kong Time
Newsgroup:  news.mozilla.org/mozilla.dev.security.policy
Subject:  

RE: DigiCert validation issue

NNTP-Posting-Host:  63.245.210.105

Here's the link: https://bugzilla.mozilla.org/show_bug.cgi?id=1556948


-----Original Message-----
From: dev-security-policy  On
Behalf Of Jeremy Rowley via dev-security-policy
Sent: Wednesday, June 5, 2019 12:17 AM
To: mozilla-dev-security-policy@lists.mozilla.org
Subject: DigiCert validation issue

I just posted this incident report.  The summary is we had an issue where a
certain path allowed issuance of certs for example.com when only
www.example.com   was verified. This incident
happened previously with Comodo here:
https://groups.google.com/forum/#!msg/mozilla.dev.security.policy/PoMZvss_PR
o/TK8L-lK0EwAJ. At that time we checked out code, but missed a path.