Sectigo: Use of forbidden subjectPublicKeyInfo algorithm
This case involves Sectigo's discovery of the issuance of certificates using the forbidden P-521 public key algorithm, which violates Mozilla's CA policy. The issue was first reported in the mozilla.dev.security.policy forum, prompting Sectigo to investigate and disclose the incident. Sectigo implemented a code change to prevent further issuance of such certificates and conducted a compliance review, identifying additional issues related to RSA key sizes. The CA has committed to improving its QA processes and has provided a timeline for remediation. The case is now resolved with the necessary actions taken.
- Sectigo discovered the issuance of certificates with the P-521 public key algorithm.
- Sectigo implemented a further code change to prevent issuance of certificates with P-521 keys.
- Community commenter — Reported problems with certificates issued by Sectigo, requesting an incident report.
- Sectigo — Confirmed immediate code change to stop issuing certificates with P-521 keys.
- Sectigo — Identified additional compliance issues regarding RSA key sizes.
- Sectigo — Confirmed final remediation actions and improvements to QA processes.
- Fastly representative — Noted that all questions have been answered and remediation is complete.