← Sectigo cases
Bugzilla #1597950 Ca Certificate Compliance Incident

Sectigo: CCADB failed ALV results (Ensured Root CA)

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported that CCADB showed “Failed ALV results” for intermediate CA certificates, and this bug addresses two of nine affected CA certificates. Robin Alden said an email from Kathleen alerted Sectigo to the CCADB report, which indicated nine intermediate CA certificates with failed ALV results; this ticket covers “Ensured Document Signing CA” and an older “Ensured Root CA” version (now revoked). Sectigo stated that the older Ensured Root CA was re-issued in 2016 under a new certificate ID, and that the original version was not used after 2016. Sectigo said it revoked the original Ensured Root CA on 6 November 2019, which removed both listed CA certificates from the Failed ALV report. In the thread, Mozilla asked why the Ensured Document Signing CA was not revoked/added to OneCRL, and Sectigo responded that it was not of interest because OneCRL is only used by Firefox and Firefox would not accept certificates chaining to that intermediate due to EKU OIDs; Sectigo also argued the trust path went through the revoked root already in OneCRL. Mozilla later noted remaining ALV failures for other Sectigo intermediate CAs and Sectigo stated those were false positives that should disappear once Sectigo’s current CCADB audit case is processed. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:18 UTC Revised: 2026-06-16 18:41 UTC Confidence: 0.86 8 comments
Chronology
  1. Cross-signed and subordinate CA certificates were issued for the USERTrust RSA Certification Authority to Ensured Root CA and for Ensured Root CA to Ensured Document Signing CA.
  2. A cross-signed CA certificate for USERTrust RSA Certification Authority to Ensured Root CA was issued with a replacement Ensured Root CA key.
  3. Sectigo began evaluating options to fix failed ALV results in CCADB.
  4. Sectigo revoked the older Ensured Root CA certificate, removing the related intermediate from the Failed ALV report.
  5. Mozilla asked whether the bug could be closed; Mozilla also reported remaining ALV failures for other intermediate CAs and Sectigo addressed them as false positives.
Thread Activity
  1. Sectigo — Robin Alden opened the bug after an email alerting Sectigo to CCADB “Failed ALV results,” explaining this ticket covers the Ensured Document Signing CA and an older Ensured Root CA version that was later revoked and re-issued.
  2. Sectigo — Robin provided a detailed timeline and stated that revoking the older Ensured Root CA on 6 Nov 2019 removed both CA certificates from the Failed ALV report.
  3. Mozilla representative — Ben Wilson asked why the Ensured Document Signing CA certificate was not revoked and/or added to OneCRL.
  4. Sectigo — Rob (Sectigo) responded that Firefox would not accept certificates chaining to the intermediate due to EKU OIDs and argued the trust path already went through the revoked root in OneCRL.
  5. Mozilla representative — Ben Wilson said he was initially confused by the sequence of events but could move on.
  6. Sectigo — Rob asked whether the bug could be closed now.
  7. Mozilla representative — Ben Wilson said CCADB still showed two ALV failures for other Sectigo intermediate CAs and asked how they should be handled.
  8. Sectigo — Rob stated the remaining ALV failures were false positives due to deliberately backdated notBefore dates and said they should disappear after Sectigo’s current CCADB audit case is processed.
Participants
Sectigo Mozilla representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1593776 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-04 · Closed 2023-02-22 · 100% similar
Sectigo: invalid subject:organizationalUnitName on DV certificates
#1741777 RESOLVED Incident Opened 2021-11-18 · Closed 2023-02-22 · 95% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1597947 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-20 · Closed 2023-02-22 · 95% similar
Sectigo: CCADB failed ALV - Network Solutions Certificate Authority
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 94% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 93% similar
Sectigo: Subject field with unvalidated information included in certificates
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 90% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 90% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action