← Sectigo cases
Bugzilla #1635840 Delayed Revocation

Sectigo: Failure to properly respond to a report of subscriber key compromise

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported an incident where it did not properly respond to a report of subscriber key compromise. The reporter stated that evidence of a compromised subscriber key was provided to Sectigo on 1 May 2020, but Sectigo did not acknowledge it as valid and the certificate using the compromised key was not revoked. In the thread, Sectigo described receiving an email on 1 May 2020 claiming to attach CSR evidence of compromise, responding that the CSR was not the correct CSR, and requesting additional proof, including details about how the private key was obtained. Sectigo later revoked the certificate identified by https://crt.sh/?id=2081585376 on 6 May 2020. Mozilla staff closed the incident as appropriately explained, documented, and remediated. A commenter later noted they did not see an indication of what remediation was performed to prevent the same incident from happening again in the future.

Model: gpt-5.4-nano Generated: 2026-06-13 20:58 UTC Revised: 2026-06-16 18:44 UTC Confidence: 0.86 4 comments
Chronology
  1. Sectigo received an email claiming evidence of subscriber key compromise but initially did not acknowledge it as valid.
  2. Sectigo revoked the certificate identified by crt.sh ID 2081585376.
  3. Mozilla closed the incident as appropriately explained, documented, and remediated.
Thread Activity
  1. Sectigo — A report was posted to mozilla.dev.security.policy stating evidence of a compromised subscriber key was provided to Sectigo on 1 May 2020, but the certificate was not revoked; Alden acknowledged the incident and said Sectigo would follow up with an incident report in the expected format.
  2. Sectigo — Alden provided a timeline describing Sectigo’s email exchanges and stated that Sectigo revoked the certificate https://crt.sh/?id=2081585376 on 6 May 2020.
  3. Mozilla representative — Mozilla stated the incident appears appropriately explained, documented, and remediated and closed it.
  4. Hezmatt representative — Commenter said they did not see any indication of what remediation was performed to prevent the same incident from happening again in the future.
Participants
Sectigo Mozilla representative Hezmatt representative
Similar Local Cases
#1639804 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 95% similar
Sectigo: Failure to revoke key-compromised certificate within 24 hours
#1639805 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 95% similar
Sectigo: Failure to revoke key-compromised certificates
#1625715 RESOLVED Delayed Revocation Opened 2020-03-29 · Closed 2023-02-22 · 89% similar
Sectigo: Failure to revoke certificate with previously-compromised key within 24 hours
#1800756 RESOLVED Delayed Revocation Opened 2022-11-15 · Closed 2023-02-22 · 88% similar
Sectigo: Failure to revoke ECC certificates with non-DER encoded keyUsage within 5 days
#1818073 RESOLVED Delayed Revocation Opened 2023-02-21 · Closed 2023-06-28 · 87% similar
Sectigo: Late revocation for incomplete Subject organizationName
#1665763 RESOLVED Delayed Revocation Opened 2020-09-17 · Closed 2023-02-22 · 86% similar
Sectigo: Failure to revoke within 5 days
#1698936 RESOLVED Delayed Revocation Opened 2021-03-16 · Closed 2023-02-22 · 86% similar
Sectigo: ZeroSSL: failure to revoke within 24 hours
#1813989 RESOLVED Delayed Revocation Opened 2023-01-31 · Closed 2023-05-04 · 80% similar
Sectigo: Incomplete Subject organizationName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action