← Sectigo cases
Bugzilla #1545208 Policy Document Issue

Sectigo: Missing changelog in CPS

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Sectigo’s Certificate Practice Statement (CPS) lacking an apparent changelog, which Mozilla Root Store Policy requires. The issue was raised in this Bugzilla report after Wayne Thayer opened bug 1545208 on 2019-04-17, citing Mozilla Root Store Policy section 3.3 and pointing to Sectigo’s CPS v5.0 PDF. Sectigo stated that internal compliance review processes had missed the introduction of the requirement for a dated changelog entry when Mozilla policy version 2.5 was introduced, and that they created CPS v5.1.1 (and later v5.1.2) including a changelog reaching back to version 5.0. Sectigo also stated it would maintain the changelog for each CPS update going forward and published updated CPS documents, including a later CPS revision v5.1.4. Robin Alden later confirmed the compliance review was completed on 2019-07-17 and that the CPS update went live on 2019-08-15, providing a link to the updated CPS v5.1.4. The reporter indicated on 2019-09-18 that remediation appeared complete, and the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 18:11 UTC Revised: 2026-06-16 18:34 UTC Confidence: 0.86 9 comments
Chronology
  1. Wayne Thayer opened Bug 1545208 reporting that Sectigo’s CPS v5.0 lacked an apparent required changelog.
  2. Sectigo created CPS v5.1.1 with a changelog reaching back to version 5.0 after identifying the missing requirement.
  3. Sectigo published CPS v5.1.1 as the current CPS version.
  4. Sectigo approved and published CPS v5.1.2, updating the changelog.
  5. Sectigo completed a compliance review related to Mozilla policy compliance and CPS statements.
  6. Sectigo published CPS v5.1.4 on its website, including the changelog update.
  7. The reporter indicated remediation appeared complete after the CPS update link was provided.
Thread Activity
  1. Fastly representative — Wayne Thayer reported that Sectigo’s CPS v5.0 had no apparent changelog as required by Mozilla Root Store Policy section 3.3 and asked for an explanation or an incident report.
  2. Community commenter — Ryan Sleevi noted another Sectigo incident had gone unresponded to for a long period of time.
  3. Sectigo — Robin Alden provided a detailed response including how Sectigo became aware, a timeline of CPS updates (v5.1.1/v5.1.2), and explanations about why the changelog requirement was missed.
  4. Sectigo — Robin Alden said they did not yet have confirmation the compliance review was completed and would confirm early the next week.
  5. Sectigo — Robin Alden confirmed the compliance review was completed on 2019-07-17 and said a further CPS revision was being prepared to include expanded statements and a changelog entry.
  6. Sectigo — Robin Alden said the CPS update would be live in the next couple of days.
  7. Fastly representative — Wayne Thayer asked whether the CPS had been updated and requested a link.
  8. Sectigo — Robin Alden provided a link stating the CPS revision went live on 2019-08-15: https://sectigo.com/uploads/files/Sectigo-CPS-v5.1.4.pdf
  9. Fastly representative — Wayne Thayer stated it appeared all questions had been answered and remediation was complete.
Participants
Fastly representative Sectigo Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1596931 RESOLVED Ca Documents Policy Document Issue Opened 2019-11-15 · Closed 2024-06-30 · 77% similar
DigiCert: Verizon CPS lacks CPR problem reporting instructions
#1717034 RESOLVED Ca Documents Policy Document Issue Opened 2021-06-17 · Closed 2023-02-22 · 68% similar
Asseco DS / Certum: CPS does not refer to BR domain validation methods
#1650234 RESOLVED Ca Documents Policy Document Issue Opened 2020-07-02 · Closed 2023-02-22 · 67% similar
PKIoverheid / QuoVadis: CPS inconsistencies
#1468000 RESOLVED Policy Document Issue Opened 2018-06-09 · Closed 2025-08-21 · 67% similar
Camerfirma: Invalid country field for Camerfirma root CA certificates
#1650234 RESOLVED Policy Document Issue Opened 2020-07-02 · Closed 2023-02-22 · 66% similar
PKIoverheid / QuoVadis: CPS inconsistencies
#2007116 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Externally Reported Incident Opened 2025-12-19 Still Open · 60% similar
D-Trust: CRL URL Disclosure
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 60% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1972547 RESOLVED Incident Policy Document Issue Opened 2025-06-17 · Closed 2025-07-16 · 60% similar
Sectigo: Lack of technical controls for multiparty control access to Secure Zone

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action