Sectigo: Failure to revoke key-compromised certificate within 24 hours
This case concerns Sectigo's failure to revoke a certificate linked to a compromised key within the required 24-hour timeframe. The issue was reported on May 13, 2020, and the revocation was not completed until May 15, 2020. Sectigo acknowledged the delay and attributed it to staffing challenges exacerbated by COVID-19, which affected their ability to process problem reports in a timely manner. Following discussions in the thread, Sectigo has committed to accepting key compromise reports via email again, alongside their existing automated mechanisms. The case has been resolved with a commitment to improve their response processes.
- A certificate problem report was received regarding a compromised key.
- The compromised certificate was revoked.
- Hezmatt representative — Reported the failure to revoke the compromised certificate within the required timeframe.
- Sectigo — Acknowledged the report and promised to follow up.
- Sectigo — Confirmed that Sectigo will accept key compromise reports via email again.