← Sectigo cases
Bugzilla #1653504 Ca Certificate Compliance Certificate Misissuance

Sectigo: Certificates with RSA keys where modulus is not divisible by 8

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Sectigo certificates whose RSA key modulus size in bits was not divisible by 8, which Sectigo identified as non-compliant with the relevant requirement. Sectigo first became aware of additional affected certificates after an email from Jeremy (Digicert) on 2020-07-17, and Sectigo assessed the list and found 32 certificates total, including two certificates that were not on the earlier list from bug 1518553. Sectigo revoked the two missed certificates on 2020-07-17. Sectigo later re-ran scans over its issued-certificate corpus and identified an additional ten certificates that were not on the earlier list; Sectigo stated these were already being processed for revocation and would be revoked on or before 2020-08-02 6am UTC. Sectigo also described that its earlier reporting was based on CT log data (via crt.sh) and that some older certificates may not have appeared in CT logs, leading to missed detection until Jeremy’s report. The bug was marked RESOLVED with resolution FIXED, and a later bug (1725041) was marked as a duplicate of this bug.

Model: gpt-5.4-nano Generated: 2026-06-13 20:58 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.86 9 comments
Chronology
  1. Bug 1518553 was opened covering issuance of certificates with the p521 curve and RSA keys of incorrect size.
  2. Sectigo received a report identifying certificates with incorrect RSA key sizes and revoked two missed certificates.
  3. Sectigo stated it would revoke an additional set of non-compliant certificates by this deadline.
Thread Activity
  1. Sectigo — Nick France explained how Sectigo became aware of the issue, identified two certificates missed from the earlier list, and stated those certificates were revoked.
  2. Community commenter — Ryan Sleevi asked for more thorough analysis and questioned whether Sectigo had institutionalized lessons from other CA incidents.
  3. Sectigo — Nick France said a more detailed update would be posted soon with expanded sections 6 and 7.
  4. Sectigo — Nick France expanded on how the reporting missed certificates, described additional certificates found via a scan, and stated they were being processed for revocation.
  5. Sectigo — Rob Stradling shared a spreadsheet of scan results and said Sectigo was confirming externally-operated CAs’ compliance, awaiting responses from Apple and D-TRUST.
  6. Sectigo — Rob Stradling stated Apple had not issued non-compliant certificates and expected a response from D-TRUST.
  7. Sectigo — Rob Stradling stated D-TRUST had not issued any certificates that fell foul of the modulus-divisible-by-8 requirement.
  8. Sectigo — Rob Stradling asked whether the bug could be closed.
  9. Mozilla representative — Mozilla marked Bug 1725041 as a duplicate of this bug.
Participants
Sectigo Community commenter Mozilla representative
Similar Local Cases
#1590810 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-23 · Closed 2023-02-22 · 100% similar
Sectigo: EV SSL Certificates with incorrect businessCategory
#1718579 RESOLVED Certificate Misissuance Opened 2021-06-29 · Closed 2023-02-22 · 91% similar
Sectigo: "Manual DCV" method used
#1915883 RESOLVED Certificate Misissuance Opened 2024-08-30 · Closed 2024-09-26 · 90% similar
Sectigo: Missing data in cabfOrganizationIdentifier
#1747915 RESOLVED Certificate Misissuance Opened 2021-12-29 · Closed 2023-02-22 · 89% similar
Sectigo: Incorrect JOI Country value
#1891245 RESOLVED Certificate Misissuance Opened 2024-04-12 · Closed 2024-05-13 · 89% similar
Sectigo: EV Certificate issuance with incorrect subject:serialNumber attribute value
#1895722 RESOLVED Certificate Misissuance Opened 2024-05-08 · Closed 2024-06-05 · 89% similar
Sectigo: Incorrect inclusion of DBA name
#1902748 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-06-14 · Closed 2026-06-10 · 89% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 88% similar
QuoVadis: Incorrect keyUsage for ECC certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action