Sectigo: ZeroSSL: failure to revoke within 24 hours
This case involves Sectigo's ZeroSSL failing to revoke a compromised certificate within the required 24-hour timeframe. The issue was reported when a user encountered an error while attempting to revoke the certificate through the ZeroSSL web portal. Following the report, the certificate was eventually revoked. However, Sectigo indicated that the proper revocation process was not followed, as the user contacted ZeroSSL directly instead of using the designated problem reporting mechanisms. The case was resolved with the certificate being revoked, and the discussion highlighted the need for clearer communication regarding the revocation process for certificates issued through ZeroSSL.
- User reported failure to revoke a compromised certificate through ZeroSSL.
- ZeroSSL clarified its revocation process and updated its terms to reflect the relationship with Sectigo.
- Sectigo confirmed the certificate was revoked and addressed the confusion regarding the revocation process.
- Marget representative — User reported an error when trying to revoke a certificate through ZeroSSL.
- Sectigo — Sectigo stated that the proper problem reporting mechanisms were not used.
- Sectigo — Sectigo confirmed that the certificate was revoked and clarified the revocation process.