← Sectigo cases
Bugzilla #1545208 Policy Compliance

Sectigo: Missing Changelog in CPS

RESOLVED FIXED Sectigo
AI Summary

Sectigo faced an issue regarding the absence of a changelog in their Certificate Practice Statement (CPS), which is a requirement under Mozilla's Root Store Policy. The problem was identified on April 17, 2019, leading to a series of internal discussions and actions. Sectigo acknowledged the oversight and subsequently published updated versions of their CPS that included the required changelog. The compliance review confirmed that their practices are now in line with Mozilla's policies, and the necessary updates were made to their documentation.

Model: gpt-4o-mini Generated: 2026-06-13 18:11 UTC Confidence: 0.95
Chronology
  1. Bug created regarding missing changelog
  2. Internal discussions led to realization of missed requirement
  3. CPS v5.1.2 published with updated changelog
  4. Compliance review completed
  5. CPS revision went live
Participants
Wayne Thayer Robin Alden Ryan Sleevi
External References
Similar Local Cases
#1625715 RESOLVED Policy Compliance Opened 2020-03-29 · Closed 2023-02-22 · 67% similar
Sectigo: Failure to revoke certificate with previously-compromised key within 24 hours
#1596949 RESOLVED Policy Compliance Opened 2019-11-15 · Closed 2023-02-22 · 60% similar
FNMT: CP/CPS lack CAA processing details
#1596923 RESOLVED Policy Compliance Opened 2019-11-15 · Closed 2024-06-30 · 58% similar
PKIoverheid: KPN CPS lacks CPR problem reporting instructions
#1374381 RESOLVED Policy Compliance Opened 2017-06-19 · Closed 2023-02-22 · 57% similar
SwissSign: BRs require full annual audits
#1650910 RESOLVED Policy Compliance Opened 2020-07-06 · Closed 2023-02-22 · 56% similar
DigiCert: Inconsistent EV audits
#1391429 RESOLVED Policy Compliance Opened 2017-08-17 · Closed 2024-02-27 · 56% similar
GoDaddy: Non-BR-Compliant Certificate Issuance
#1612389 RESOLVED Policy Compliance Opened 2020-01-30 · Closed 2023-02-22 · 55% similar
Google Trust Services: invalid curve-hash combination
#1586795 RESOLVED Policy Compliance Opened 2019-10-07 · Closed 2023-02-22 · 55% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action