← Sectigo cases
Bugzilla #1699756 Technical Compliance

Sectigo: Reseller ZeroSSL and Private Key Generation

RESOLVED INVALID Sectigo
AI Summary

This case discusses the private key generation and storage practices of ZeroSSL, a reseller of Sectigo. Concerns were raised regarding whether ZeroSSL's method of generating and storing private keys complies with Mozilla's Root Store Policy. The discussion highlighted that private keys are generated client-side and encrypted before being sent to ZeroSSL's servers. However, questions about the security of this process and the implications of storing encrypted private keys were debated. Ultimately, the case was closed as invalid after it was determined that the processes in place do not expose private keys improperly.

Model: gpt-4o-mini Generated: 2026-06-13 20:58 UTC Confidence: 0.90
Chronology
  1. Initial concerns raised about ZeroSSL's private key generation process.
  2. Further discussions on the security of ZeroSSL's practices.
  3. Case closed as invalid after review.
Participants
Ben Wilson Tim Callan David Spitzer Matthias
Similar Local Cases
#1830088 RESOLVED Technical Compliance Opened 2023-04-26 · Closed 2024-03-27 · 55% similar
Sectigo: Late termination of privileged access to Certificate Systems
#1735761 RESOLVED Technical Compliance Opened 2021-10-14 · Closed 2023-02-22 · 54% similar
Sectigo: CRL validity beyond CPS allowed value
#1716902 RESOLVED Technical Compliance Opened 2021-06-17 · Closed 2023-02-22 · 53% similar
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6
#1873739 RESOLVED Technical Compliance Opened 2024-01-09 · Closed 2024-02-09 · 47% similar
Google Trust Services: uses "DNSSec-mostly" and DTPs for DNS resolution
#1972547 RESOLVED Technical Compliance Opened 2025-06-17 · Closed 2025-07-16 · 47% similar
Sectigo: Lack of technical controls for multiparty control access to Secure Zone
#1718680 RESOLVED Technical Compliance Opened 2021-06-29 · Closed 2023-02-22 · 45% similar
Asseco DS / Certum: Forward dating certificates (notBefore in the future)
#1651611 RESOLVED Technical Compliance Opened 2020-07-09 · Closed 2023-02-22 · 45% similar
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations
#1771722 RESOLVED Technical Compliance Opened 2022-05-30 · Closed 2023-02-22 · 44% similar
Firmaprofesional: 2022 - Title field

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action