← Sectigo cases
Bugzilla #1518553 Ca Certificate Compliance

Sectigo: Use of forbidden subjectPublicKeyInfo algorithm

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Sectigo's discovery of the issuance of certificates using the forbidden P-521 public key algorithm, which violates Mozilla's CA policy. The issue was first reported in the mozilla.dev.security.policy forum, prompting Sectigo to investigate and disclose the incident. Sectigo implemented a code change to prevent further issuance of such certificates and conducted a compliance review, identifying additional issues related to RSA key sizes. The CA has committed to improving its QA processes and has provided a timeline for remediation. The case is now resolved with the necessary actions taken.

Model: gpt-4o-mini Generated: 2026-06-13 17:57 UTC Revised: 2026-06-16 18:32 UTC Confidence: 0.90 17 comments
Chronology
  1. Sectigo discovered the issuance of certificates with the P-521 public key algorithm.
  2. Sectigo implemented a further code change to prevent issuance of certificates with P-521 keys.
Thread Activity
  1. Community commenter — Reported problems with certificates issued by Sectigo, requesting an incident report.
  2. Sectigo — Confirmed immediate code change to stop issuing certificates with P-521 keys.
  3. Sectigo — Identified additional compliance issues regarding RSA key sizes.
  4. Sectigo — Confirmed final remediation actions and improvements to QA processes.
  5. Fastly representative — Noted that all questions have been answered and remediation is complete.
Participants
Community commenter Sectigo Fastly representative
Similar Local Cases
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 100% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1593776 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-04 · Closed 2023-02-22 · 97% similar
Sectigo: invalid subject:organizationalUnitName on DV certificates
#1720744 RESOLVED Ca Certificate Compliance Opened 2021-07-15 · Closed 2023-02-22 · 88% similar
Sectigo: State name in localityName
#1724458 RESOLVED Ca Certificate Compliance Opened 2021-08-06 · Closed 2023-02-22 · 88% similar
Sectigo: Mojibake in certificate Subject fields
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 87% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 87% similar
Sectigo: CPR response issues
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 86% similar
Sectigo: Incorrect JOI for federal credit unions

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action