← Sectigo cases
Bugzilla #1635840 Certificate Problem Report

Sectigo: Failure to properly respond to a report of subscriber key compromise

RESOLVED FIXED Sectigo
AI Summary

Sectigo faced a challenge in responding to a report of a compromised subscriber key. The report was submitted on May 1, 2020, but Sectigo did not initially acknowledge it as valid, leading to delays in revocation of the affected certificate. After further communication and investigation, the certificate was ultimately revoked on May 6, 2020. The incident raised concerns about the speed of response to revocation requests, although it was documented and remediated appropriately.

Model: gpt-4o-mini Generated: 2026-06-13 20:58 UTC Confidence: 0.90
Chronology
  1. Sectigo received a report of a compromised subscriber key.
  2. Sectigo revoked the certificate in question.
  3. Incident was closed after appropriate documentation and remediation.
Participants
Robin Alden bwilson@mozilla.com mpalmer@hezmatt.org
Similar Local Cases
#1639804 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 66% similar
Sectigo: Failure to revoke key-compromised certificate within 24 hours
#1597948 RESOLVED Certificate Problem Report Opened 2019-11-20 · Closed 2024-06-30 · 63% similar
Sectigo: Missing Intermediate CA Certificate in Audit - D-TRUST CA 2-1 2015
#1639805 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 60% similar
Sectigo: Failure to revoke key-compromised certificates
#1619359 RESOLVED Certificate Problem Report Opened 2020-03-02 · Closed 2023-02-22 · 59% similar
Sectigo: Failure to provide a preliminary report within 24 hours
#1492006 RESOLVED Certificate Problem Report Opened 2018-09-18 · Closed 2023-02-22 · 58% similar
Sectigo: Failure to revoke within 24 hours
#1551362 RESOLVED Certificate Problem Report Opened 2019-05-14 · Closed 2023-02-22 · 58% similar
Sectigo: "Some-State" in stateOrProvinceName
#1563579 RESOLVED Certificate Problem Report Opened 2019-07-04 · Closed 2023-02-22 · 58% similar
Sectigo: Failure to provide timely incident reports
#1639799 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 57% similar
GlobalSign: Failure to revoke key-compromised certificate within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action