← Sectigo cases
Bugzilla #1563579 Ca Certificate Compliance Self Reported Incident

Sectigo incident report on repeated delays in responding to Mozilla incident reports

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Sectigo’s repeated failure to provide timely responses to Mozilla incident reports. It was opened by Mozilla after Ryan Sleevi cited a pattern across several other Sectigo bugs where responses were delayed beyond Mozilla’s expected one-week update cadence. Sectigo acknowledged the concern and said it would treat the matter as an incident report, then described the underlying cause as being under-resourced in people with the right skills for detailed incident reporting. Over time, Sectigo said it created a leadership group, increased meeting cadence, introduced a buddy system for bug ownership, and continued to refine its incident-response process. The bug was later marked resolved/fixed, and Sectigo said this bug was ready to close after a dependent bug was closed.

Model: gpt-5.4-mini Generated: 2026-06-13 18:16 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.96 63 comments
Chronology
  1. Mozilla opened a case about Sectigo’s delayed incident-report responses after citing multiple prior bugs.
  2. Sectigo provided an incident-response explanation and said it would respond promptly and weekly thereafter.
  3. Sectigo described root causes for the delays and outlined process changes to improve incident handling.
  4. Sectigo said it had increased the working-meeting cadence to twice per week and added a buddy system for bug co-ownership.
  5. Sectigo said this bug was ready to close after its dependency was closed.
Thread Activity
  1. Community commenter — Ryan Sleevi opened the bug, said Sectigo had a worrying pattern of not responding to incident reports in time, and asked for an explanation and prevention steps.
  2. Sectigo — Robin Alden said Sectigo would follow up the next week.
  3. Sectigo — Robin Alden said the underlying cause was under-resourcing for detailed incident reporting and committed to weekly updates and remediation work.
  4. Sectigo — Rob Stradling said Sectigo had identified root causes for the lack of timeliness and was putting measures in place to improve incident response.
  5. Sectigo — Tim Callan said a combination of user error and PTO caused gaps in the seven-day update window and that Sectigo had increased meeting cadence and added co-owners for each bug.
  6. Sectigo — Tim Callan said Sectigo was still tracking open issues and responding within the specified timeframes, and that this bug remained open for community discussion and dependency reasons.
  7. Sectigo — Tim Callan said that because the dependent bug was closed, this bug was ready to close too.
  8. Mozilla representative — Ben Wilson said he would close the bug on or about 7-Apr-2021 unless someone objected.
Participants
Community commenter Sectigo Mozilla representative Fastly representative Hezmatt representative Thisisntrocket representative
Similar Local Cases
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 100% similar
Sectigo: Incorrect OCSP responses
#1518553 RESOLVED Ca Certificate Compliance Opened 2019-01-08 · Closed 2023-02-22 · 100% similar
Sectigo: Use of forbidden subjectPublicKeyInfo algorithm
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 100% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1593776 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-04 · Closed 2023-02-22 · 100% similar
Sectigo: invalid subject:organizationalUnitName on DV certificates
#1597950 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-20 · Closed 2023-02-22 · 100% similar
Sectigo: CCADB failed ALV - Ensured Root CA
#1620561 RESOLVED Self Reported Incident Opened 2020-03-06 · Closed 2023-02-22 · 100% similar
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 100% similar
Sectigo: CPR response issues
#1699756 RESOLVED Self Reported Incident Opened 2021-03-19 · Closed 2022-11-14 · 100% similar
Sectigo: Reseller ZeroSSL and Private Key Generation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action