Sectigo: CCADB failed ALV results (Ensured Root CA)
Sectigo reported that CCADB showed “Failed ALV results” for intermediate CA certificates, and this bug addresses two of nine affected CA certificates. Robin Alden said an email from Kathleen alerted Sectigo to the CCADB report, which indicated nine intermediate CA certificates with failed ALV results; this ticket covers “Ensured Document Signing CA” and an older “Ensured Root CA” version (now revoked). Sectigo stated that the older Ensured Root CA was re-issued in 2016 under a new certificate ID, and that the original version was not used after 2016. Sectigo said it revoked the original Ensured Root CA on 6 November 2019, which removed both listed CA certificates from the Failed ALV report. In the thread, Mozilla asked why the Ensured Document Signing CA was not revoked/added to OneCRL, and Sectigo responded that it was not of interest because OneCRL is only used by Firefox and Firefox would not accept certificates chaining to that intermediate due to EKU OIDs; Sectigo also argued the trust path went through the revoked root already in OneCRL. Mozilla later noted remaining ALV failures for other Sectigo intermediate CAs and Sectigo stated those were false positives that should disappear once Sectigo’s current CCADB audit case is processed. The bug is marked RESOLVED with resolution FIXED.
- Cross-signed and subordinate CA certificates were issued for the USERTrust RSA Certification Authority to Ensured Root CA and for Ensured Root CA to Ensured Document Signing CA.
- A cross-signed CA certificate for USERTrust RSA Certification Authority to Ensured Root CA was issued with a replacement Ensured Root CA key.
- Sectigo began evaluating options to fix failed ALV results in CCADB.
- Sectigo revoked the older Ensured Root CA certificate, removing the related intermediate from the Failed ALV report.
- Mozilla asked whether the bug could be closed; Mozilla also reported remaining ALV failures for other intermediate CAs and Sectigo addressed them as false positives.
- Sectigo — Robin Alden opened the bug after an email alerting Sectigo to CCADB “Failed ALV results,” explaining this ticket covers the Ensured Document Signing CA and an older Ensured Root CA version that was later revoked and re-issued.
- Sectigo — Robin provided a detailed timeline and stated that revoking the older Ensured Root CA on 6 Nov 2019 removed both CA certificates from the Failed ALV report.
- Mozilla representative — Ben Wilson asked why the Ensured Document Signing CA certificate was not revoked and/or added to OneCRL.
- Sectigo — Rob (Sectigo) responded that Firefox would not accept certificates chaining to the intermediate due to EKU OIDs and argued the trust path already went through the revoked root in OneCRL.
- Mozilla representative — Ben Wilson said he was initially confused by the sequence of events but could move on.
- Sectigo — Rob asked whether the bug could be closed now.
- Mozilla representative — Ben Wilson said CCADB still showed two ALV failures for other Sectigo intermediate CAs and asked how they should be handled.
- Sectigo — Rob stated the remaining ALV failures were false positives due to deliberately backdated notBefore dates and said they should disappear after Sectigo’s current CCADB audit case is processed.