Re: Sectigo-issued certificates with concerningly mismatched subject information

2020-01-26 Thread Nick Lamb via dev-security-policy
On Sun, 26 Jan 2020 11:16:24 +0100 Hanno Böck via dev-security-policy wrote: > I guess this is the most relevant part here. Noone has noticed. > > I see that a lot of people are having fun pointing out these issues > again and again to show how sloppy CAs work. Which is fine I guess, > but it

Re: Sectigo-issued certificates with concerningly mismatched subject information

2020-01-26 Thread Hanno Böck via dev-security-policy
On Sun, 26 Jan 2020 01:59:33 -0800 (PST) Ian Carroll via dev-security-policy wrote: > These certificates expired in 2019 and are thus no longer a problem, > but they were actively used by the customer (e.infinityspeakers.com > still serves one of them) and it does not appear anyone has noticed.

Sectigo-issued certificates with concerningly mismatched subject information

2020-01-26 Thread Ian Carroll via dev-security-policy
Hi, I was recently sent https://crt.sh/?id=380678631 by Nathanial Lattimer (https://twitter.com/d0nutptr), when he noticed it appeared to contain subject information for a completely different entity (Harman International's domain, Twitter's organizational information). It appears Sectigo made