← Sectigo cases
Bugzilla #1635840
Certificate Problem Report
Sectigo: Failure to properly respond to a report of subscriber key compromise
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo faced a challenge in responding to a report of a compromised subscriber key. The report was submitted on May 1, 2020, but Sectigo did not initially acknowledge it as valid, leading to delays in revocation of the affected certificate. After further communication and investigation, the certificate was ultimately revoked on May 6, 2020. The incident raised concerns about the speed of response to revocation requests, although it was documented and remediated appropriately.
Chronology
- Sectigo received a report of a compromised subscriber key.
- Sectigo revoked the certificate in question.
- Incident was closed after appropriate documentation and remediation.
Participants
Robin Alden
bwilson@mozilla.com
mpalmer@hezmatt.org
External References
Similar Local Cases
Sectigo: Failure to revoke key-compromised certificate within 24 hours
Sectigo: Missing Intermediate CA Certificate in Audit - D-TRUST CA 2-1 2015
Sectigo: Failure to revoke key-compromised certificates
Sectigo: Failure to provide a preliminary report within 24 hours
Sectigo: Failure to revoke within 24 hours
Sectigo: "Some-State" in stateOrProvinceName
Sectigo: Failure to provide timely incident reports
GlobalSign: Failure to revoke key-compromised certificate within 24 hours