Sectigo: Forbidden Domain Validation Method
Sectigo disclosed a compliance issue regarding their Domain Control Validation (DCV) methods, specifically that their Certificate Policy Statement (CPS) was not fully updated to reflect supported DCV methods. This was identified during a review triggered by a previous bug report. Sectigo acknowledged the oversight and initiated a comprehensive review of their DCV processes, leading to the revocation of 369,922 affected certificates. The updated CPS was published on May 21, 2021, and the revocation process was completed by June 10, 2021. The CA has committed to improving their compliance processes to prevent similar issues in the future.
- Bug opened by Ryan Sleevi to track the compliance issue.
- Updated CPS published to reflect all in-production DCV methods.
- Revocation of all affected certificates completed.
- Community commenter — Sectigo disclosed that they had not kept their list of supported DCV methods fully up to date.
- Sectigo — Acknowledged the bug and stated it would be used to track the update and corresponding certificate revocations.
- Sectigo — Provided details on the timeline of actions taken in response to the issue.
- Community commenter — Expressed willingness to consider the issue resolved while highlighting concerns about prioritization.
- Sectigo — Reiterated commitment to improving issuance quality and compliance measures.