Sectigo: Failure to properly respond to a report of subscriber key compromise
Sectigo reported an incident where it did not properly respond to a report of subscriber key compromise. The reporter stated that evidence of a compromised subscriber key was provided to Sectigo on 1 May 2020, but Sectigo did not acknowledge it as valid and the certificate using the compromised key was not revoked. In the thread, Sectigo described receiving an email on 1 May 2020 claiming to attach CSR evidence of compromise, responding that the CSR was not the correct CSR, and requesting additional proof, including details about how the private key was obtained. Sectigo later revoked the certificate identified by https://crt.sh/?id=2081585376 on 6 May 2020. Mozilla staff closed the incident as appropriately explained, documented, and remediated. A commenter later noted they did not see an indication of what remediation was performed to prevent the same incident from happening again in the future.
- Sectigo received an email claiming evidence of subscriber key compromise but initially did not acknowledge it as valid.
- Sectigo revoked the certificate identified by crt.sh ID 2081585376.
- Mozilla closed the incident as appropriately explained, documented, and remediated.
- Sectigo — A report was posted to mozilla.dev.security.policy stating evidence of a compromised subscriber key was provided to Sectigo on 1 May 2020, but the certificate was not revoked; Alden acknowledged the incident and said Sectigo would follow up with an incident report in the expected format.
- Sectigo — Alden provided a timeline describing Sectigo’s email exchanges and stated that Sectigo revoked the certificate https://crt.sh/?id=2081585376 on 6 May 2020.
- Mozilla representative — Mozilla stated the incident appears appropriately explained, documented, and remediated and closed it.
- Hezmatt representative — Commenter said they did not see any indication of what remediation was performed to prevent the same incident from happening again in the future.