Sectigo: Failure to provide a preliminary report within 24 hours
This case involves Sectigo's failure to provide a preliminary report within the required 24-hour timeframe after receiving multiple Certificate Problem Reports regarding compromised keys. The issue was raised by Matt Palmer, who reported three incidents on February 26, 2020, but did not receive timely responses from Sectigo. After acknowledging the bug, Sectigo committed to providing an incident response and subsequently confirmed that the private keys in question were compromised and that the affected certificates would be revoked. The case was resolved with Sectigo implementing measures to improve their response times and processes for handling such reports.
- Multiple Certificate Problem Reports were submitted to Sectigo regarding compromised keys.
- Sectigo confirmed the compromise of the private keys and revoked the affected certificates.
- Community commenter — Reported the failure to receive a preliminary report from Sectigo.
- Sectigo — Acknowledged the bug report and committed to providing an incident response.
- Sectigo — Provided a timeline of actions taken in response to the problem reports.
- Sectigo — Described improvements made to their processes for handling key compromise reports.
- Mozilla representative — Reviewed Sectigo's response and approach, finding it sufficient and adequate.