← Sectigo cases
Bugzilla #1639804 Certificate Problem Report

Sectigo: Failure to revoke key-compromised certificate within 24 hours

RESOLVED FIXED Sectigo
AI Summary

Sectigo faced a significant issue when it failed to revoke a certificate associated with a compromised key within the mandated 24-hour timeframe. The incident was reported on May 13, 2020, and while the revocation was eventually processed by May 15, it did not meet the expected timeline. The delay was attributed to staffing challenges exacerbated by COVID-19, which affected their ability to manage problem reports efficiently. Following the incident, Sectigo acknowledged the shortcomings in their response process and committed to improving their handling of such reports, including accepting key compromise reports via email once again.

Model: gpt-4o-mini Generated: 2026-06-13 20:58 UTC Confidence: 0.90
Chronology
  1. Certificate problem report received regarding compromised key.
  2. Certificate revoked, but outside the 24-hour requirement.
  3. Sectigo acknowledged slow response and committed to follow up.
  4. Sectigo announced they would accept key compromise reports via email again.
Participants
mpalmer@hezmatt.org Robin.Alden@Sectigo.com inigo@startcomca.com ryan.sleevi@gmail.com bwilson@mozilla.com rich@sectigo.com
External References
Similar Local Cases
#1639518 RESOLVED Certificate Problem Report Opened 2020-05-20 · Closed 2025-08-18 · 73% similar
Sectigo: "unauthorized" OCSP responses
#1635840 RESOLVED Certificate Problem Report Opened 2020-05-06 · Closed 2023-02-22 · 66% similar
Sectigo: Failure to properly respond to a report of subscriber key compromise
#1639798 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 65% similar
GoDaddy: Failure to revoke key-compromised certificates within 24 hours
#1639794 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 65% similar
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
#1636141 RESOLVED Certificate Problem Report Opened 2020-05-07 · Closed 2023-02-22 · 65% similar
SwissSign: failure to provide a preliminary report within 24 hours
#1717046 RESOLVED Certificate Problem Report Opened 2021-06-17 · Closed 2022-11-14 · 65% similar
Sectigo: potentially invalid organizational validation certificates
#1639502 RESOLVED Certificate Problem Report Opened 2020-05-20 · Closed 2023-02-22 · 61% similar
Asseco DS / Certum: Incorrect OCSP response encoding
#1639799 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 61% similar
GlobalSign: Failure to revoke key-compromised certificate within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action