← Sectigo cases
Bugzilla #1699756 Self Reported Incident

Sectigo: Reseller ZeroSSL and Private Key Generation

RESOLVED INVALID Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Sectigo's reseller, ZeroSSL, and concerns the generation and storage of private keys for SSL certificates. The issue was raised regarding whether ZeroSSL's practices violated Mozilla's Root Store Policy, specifically around the generation and storage of private keys. After discussions and clarifications from ZeroSSL, it was established that private keys are generated client-side and stored securely. The Mozilla representative, Ben Wilson, ultimately concluded that the process does not expose private keys in a way that violates policy, leading to the bug being closed as invalid.

Model: gpt-4o-mini Generated: 2026-06-13 20:58 UTC Revised: 2026-06-16 18:49 UTC Confidence: 0.85 13 comments
Chronology
  1. Initial concerns raised about ZeroSSL's private key generation and storage practices.
  2. Bug closed as invalid after confirming no policy violation.
Thread Activity
  1. Mozilla representative — Raised concerns about ZeroSSL's private key generation process potentially violating Mozilla's Root Store Policy.
  2. Sectigo — Defended ZeroSSL's practices, stating they do not generate keys and thus do not violate policy.
  3. Mozilla representative — Concluded that ZeroSSL's key generation process does not present an issue and closed the bug.
Participants
Mozilla representative Sectigo Stack representative Thisisntrocket representative
External References
Similar Local Cases
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 100% similar
Sectigo: Failure to provide timely incident reports
#1620561 RESOLVED Self Reported Incident Opened 2020-03-06 · Closed 2023-02-22 · 100% similar
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 100% similar
Sectigo: CPR response issues
#1718771 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2023-02-22 · 100% similar
Sectigo: DCV Reuse after 825 days
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 94% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 93% similar
Sectigo: Subject field with unvalidated information included in certificates
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 93% similar
Sectigo: Incorrect JOI for federal credit unions
#1718785 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2024-06-30 · 93% similar
Sectigo: 2020 failure to respond to CPRs discovered

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action