← Sectigo cases
Bugzilla #1472993 Ca Documents Audit Document Opened By Ca Single Ca Owner

Sectigo audit reports and related audit-document follow-up

RESOLVED WORKSFORME Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is an audit-document thread that Sectigo opened to provide Mozilla with its WebTrust audit materials. It began in July 2018 when Sectigo said it had received its 2018 WebTrust reports shortly before the annual deadline but had not yet updated the CCADB because it was waiting for WebTrust seal URLs, so it attached the reports in Bugzilla. Mozilla then asked why the 2018 reports did not mention misissuances from that audit period, and Sectigo later said those events had not been disclosed to EY during audit evidence gathering; Sectigo said it amended its internal audit process for future cycles. The thread also records Sectigo's report that CPA Canada/WebTrust seal hosting changes affected direct access to seal URLs and the CCADB audit-letter validation process, after which Kathleen Wilson said the audit case could still be processed manually. In 2021, Ryan Sleevi pointed out that several attached audit PDFs displayed the title "SSLcom" in PDF metadata, and both Sectigo and its auditor responded that this came from inherited document metadata and said they would check for this in the future; Sectigo then attached replacement versions with the misleading titles stripped. After that, the bug continued to be used as a repository for later annual audit attachments, including 2019 through 2026 WebTrust reports and related key-generation and root audit documents. Since the previous summary, Sectigo added replacement 2026 audit-report attachments on 2026-07-01 for CA, NSR, BRSSL, EVSSL, Code Signing, and S/MIME. The bug remains resolved WORKSFORME.

Model: gpt-5.4 Generated: 2026-06-13 17:51 UTC Revised: 2026-07-04 18:21 UTC Confidence: 0.97 100 comments
Chronology
  1. Sectigo received its 2018 WebTrust audit reports.
  2. Sectigo said it would submit its annual audit reports to the CCADB using Bugzilla attachment URLs.
  3. Sectigo said misissuance events from the audit period had not been disclosed to EY during audit evidence gathering and that it amended its internal audit process.
  4. Sectigo and its auditor said misleading "SSLcom" PDF titles came from inherited document metadata and would be checked in future.
  5. Sectigo attached replacement 2021 WebTrust reports with the misleading document titles stripped.
  6. Sectigo attached its 2026 WebTrust audit reports, including CA, NSR, BRSSL, EVSSL, Code Signing, S/MIME, and MC point-in-time documents.
  7. Sectigo attached replacement 2026 audit-report files for CA, NSR, BRSSL, EVSSL, Code Signing, and S/MIME.
Thread Activity
  1. Sectigo — Sectigo opened the bug, said it had received the 2018 WebTrust reports but was still waiting for seal URLs, and attached the reports.
  2. Fastly representative — Wayne Thayer asked why the reports did not mention misissuances from the audit period and whether they had been disclosed to EY.
  3. Sectigo — Sectigo said new CPA Canada seal URLs had arrived and described problems with direct access to seal pages and audit-report downloads after the hosting change.
  4. Sectigo — Sectigo said it would stop waiting for clarification from the auditor and submit the annual audit reports to the CCADB using Bugzilla attachment URLs.
  5. Sectigo — Sectigo said the CCADB ALV tool reported that the audit letter was not found in a certified location and asked whether Mozilla and other operators would discuss this with WebTrust/CPA Canada.
  6. Mozilla representative — Kathleen Wilson said the audit case could still be processed by independently confirming authenticity with the auditor and noted that Wayne's question still needed an answer.
  7. Fastly representative — Wayne Thayer requested a response from Robin by 2018-08-03 regarding the missing misissuance discussion in the audit reports.
  8. Sectigo — Robin Alden apologized for the slow response and said he would work with the auditors to provide a full reply.
  9. Sectigo — Robin Alden said a substantive reply would be provided by the end of that week.
  10. Sectigo — Sectigo said the misissuances had not been disclosed to EY during audit evidence gathering, expressed regret, and said its internal audit process had been amended.
  11. Fastly representative — Wayne Thayer closed the bug and said it could be used to share future Comodo audit reports with Mozilla.
  12. Mozilla representative — Kathleen Wilson reopened the bug per email from Rob.
  13. Community commenter — Ryan Sleevi pointed out that several 2021 audit PDFs had the document title "SSLcom" and asked how that happened.
  14. Sectigo — Sectigo said it had asked its auditors about the PDF title issue and would add a review step to check PDF document titles.
  15. Bdo representative — The auditor said the PDF title came from inherited Microsoft Word metadata and that this would be checked in the future.
  16. Sectigo — Sectigo attached new versions of the 2021 WebTrust reports with the misleading document titles stripped.
  17. Mozilla representative — Ben Wilson attached USERTrust root audit documents, including copies saved without digital signatures and an ALV testing date-format file.
  18. Sectigo — Sectigo attached its 2026 WebTrust audit reports and a 2026 point-in-time MC document.
  19. Sectigo — Sectigo attached replacement 2026 audit-report files for CA, NSR, BRSSL, EVSSL, Code Signing, and S/MIME.
Participants
Sectigo Fastly representative Mozilla representative Community commenter Bdo representative
Similar Local Cases
#1458024 RESOLVED Ca Documents Audit Document Self Assessment Auditor Qualification Opened 2018-04-30 · Closed 2026-07-13 · 97% similar
DigiCert WebTrust Audits
#1648593 RESOLVED Ca Documents Opened 2020-06-25 · Closed 2024-06-30 · 97% similar
Sectigo: Potential audit report delay
#1565270 RESOLVED Ca Documents Opened 2019-07-11 · Closed 2023-02-22 · 85% similar
Telia: Qualified BR Audit Statement
#1606380 RESOLVED Ca Documents Opened 2019-12-30 · Closed 2023-02-22 · 85% similar
Firmaprofesional: 2019 Audit Report Findings
#1588213 RESOLVED Ca Documents Audit Finding Opened 2019-10-11 · Closed 2024-06-30 · 84% similar
IdenTrust: Missing Thumbprints for Intermediate CA certificates In Some Annual Audit Reports
#1669518 RESOLVED Audit Document Audit Delay Opened 2020-10-06 · Closed 2024-06-30 · 84% similar
PKIoverheid: Overdue audit statements for intermediate certificates
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 83% similar
Sectigo: Incorrect OCSP responses
#1549862 RESOLVED Ca Documents Audit Finding Opened 2019-05-07 · Closed 2023-02-22 · 83% similar
Entrust: Outdated audit statement for intermediate cert

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action