← Sectigo cases
Bugzilla #1639805
Certificate Problem Report
Sectigo: Failure to revoke key-compromised certificates
RESOLVED
FIXED
Sectigo
AI Summary
This case addresses Sectigo's failure to revoke certificates after reports of key compromise were submitted. Between May 7 and May 9, 2020, multiple reports were sent to Sectigo, but the certificates remained valid despite the claims of compromise. After significant delays and internal reviews, some certificates were eventually revoked, but the process was found to be flawed, leading to a systemic failure in handling key compromise reports. Sectigo has since acknowledged the issues and is implementing changes to improve their response to such incidents.
Chronology
- Bug reported regarding failure to revoke compromised certificates.
- Sectigo revoked some certificates after review.
- Sectigo provided a detailed response outlining corrective actions.
- Bug intended to be closed unless further issues arise.
Participants
Rich Smith
Matt Palmer
Ryan Sleevi
Robin Alden
Ben Wilson
External References
Similar Local Cases
Sectigo: Failure to provide a preliminary report within 24 hours.
Sectigo: Failure to provide a preliminary report within 24 hours
Sectigo: Lack of input validation in stateOrProvinceName
Sectigo: EV SSL Certificates with incorrect subject details.
DigiCert: Failure to revoke key-compromised certificates within 24 hours
Sectigo: "Some-State" in stateOrProvinceName
Sectigo: Failure to provide timely incident reports
Sectigo: CPR response issues