← Sectigo cases
Bugzilla #1625715 Policy Compliance

Sectigo: Failure to revoke certificate with previously-compromised key within 24 hours

RESOLVED FIXED Sectigo
AI Summary

Sectigo faced a compliance issue regarding the timely revocation of a certificate that utilized a previously compromised key. The incident was reported on March 20, 2020, when a notification was sent to Sectigo about the compromised key. Although the certificate was revoked on the same day, a new certificate was issued shortly after using the same compromised key, which raised concerns about adherence to Mozilla's policies. Sectigo acknowledged the oversight and has since implemented measures to ensure that certificates using compromised keys are revoked within 24 hours.

Model: gpt-4o-mini Generated: 2026-06-13 20:58 UTC Confidence: 0.90
Chronology
  1. Certificate using compromised key was reported and subsequently revoked.
  2. New certificate issued using the same compromised key.
  3. Sectigo provided an incident report detailing the timeline and actions taken.
Participants
Wayne Thayer Robin Alden Matt Palmer
External References
Similar Local Cases
#1545208 RESOLVED Policy Compliance Opened 2019-04-17 · Closed 2023-02-22 · 67% similar
Sectigo: Missing Changelog in CPS
#1942651 RESOLVED Policy Compliance Opened 2025-01-20 · Closed 2025-02-14 · 50% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1609828 RESOLVED Policy Compliance Opened 2020-01-17 · Closed 2023-02-22 · 49% similar
Camerfirma: Decision not to revoke certificates with authorityKeyIdentifier that violates Mozilla Policy
#1374381 RESOLVED Policy Compliance Opened 2017-06-19 · Closed 2023-02-22 · 49% similar
SwissSign: BRs require full annual audits
#1565494 RESOLVED Policy Compliance Opened 2019-07-12 · Closed 2024-06-30 · 49% similar
CFCA: Missed annual CPS update publication on website in 2018
#1823723 RESOLVED Policy Compliance Opened 2023-03-21 · Closed 2023-04-05 · 48% similar
Sectigo: Incomplete Subscriber Agreement provisions
#1650910 RESOLVED Policy Compliance Opened 2020-07-06 · Closed 2023-02-22 · 48% similar
DigiCert: Inconsistent EV audits
#1575530 RESOLVED Policy Compliance Opened 2019-08-21 · Closed 2023-02-22 · 48% similar
Camerfirma: Govern d'Andorra audits

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action