← Sectigo cases
Bugzilla #1648717
Certificate Problem Report
Sectigo: Failure to provide a preliminary report within 24 hours.
RESOLVED
FIXED
Sectigo
AI Summary
This case addresses Sectigo's failure to provide a preliminary report within the required 24-hour timeframe after receiving two certificate problem reports. The reports highlighted incorrect subject information in certificates. Although Sectigo acknowledged the reports and initiated revocation processes, the preliminary reports were delayed, leading to concerns about compliance with established guidelines. The issue has since been resolved, with improvements to the revocation process being implemented to prevent future occurrences.
Chronology
- Two problem reports submitted to Sectigo regarding incorrect certificate subject information.
- Sectigo acknowledged the reports but failed to provide preliminary reports within 24 hours.
- Sectigo confirmed the findings and initiated revocation of the problematic certificates.
- First round of improvements to the revocation portal went live.
Participants
George [:fozzie]
Rich Smith
Nick
Robin Alden
Ryan Sleevi
Tim Callan
External References
Similar Local Cases
Sectigo: Lack of input validation in stateOrProvinceName
Sectigo: Failure to provide timely incident reports
Sectigo: Failure to provide a preliminary report within 24 hours
Sectigo: Failure to revoke key-compromised certificates
Sectigo: Inadequate DCV
Sectigo: Mojibake in certificate Subject fields
Sectigo: invalid dnsName
Sectigo: "Default City" in Subject:localityName