← Sectigo cases
Bugzilla #1718785 Self Reported Incident Revocation Issue

Sectigo: 2020 failure to respond to CPRs discovered

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a compliance issue discovered during its WebTrust audit: for one of 45 Certificate Problem Reports selected for testing, Sectigo did not provide a preliminary report to the subscriber and the entity that filed the Certificate Problem Report, and Sectigo could not provide evidence that an investigation had started within 24 hours of receiving the report. Sectigo stated that revocation did occur less than 48 hours from the initial report, and that the flaw may have been in recording evidence of its activity. Sectigo said the issue was previously unreported and that it was reporting it now after realizing it during the audit evidence-gathering process. Sectigo explained that prior to December 2020 it had a manual process for accepting and dispositioning reports to its SSL abuse email address, and that it had been vulnerable to error; it also described that it was specifying and developing an automated response system for inbound abuse reports. Sectigo stated that it remediated the issue by using an automated response mechanism for inbound abuse reports, and that it had released this system into production on December 8, 2020. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it would be scheduled for closure on July 28, 2021.

Model: gpt-5.4-nano Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:53 UTC Confidence: 0.90 5 comments
Chronology
  1. Bug 1648717 was opened to report errors in responses to inbound problem reports.
  2. A revocation requester emailed s**********e@sectigo.com regarding a Sectigo-issued SSL certificate used in a phishing campaign.
  3. The certificate was revoked and a support email was sent advising of the revocation.
  4. Sectigo released an automated response to SSL abuse reports into production.
  5. Sectigo discovered the reporting flaw during its WebTrust audit evidence gathering.
  6. Sectigo compliance began drafting the post after realizing the error remained unreported.
  7. Mozilla scheduled the bug for closure.
Thread Activity
  1. Sectigo — Tim Callan described how Sectigo became aware of the issue during its WebTrust audit, provided a timeline, and stated remediation via an automated response mechanism released on December 8, 2020.
  2. Sectigo — Tim Callan asked whether there were any questions.
  3. Sectigo — Tim Callan said there was nothing to add and that the bug was ready for closing.
  4. Mozilla representative — Ben Wilson said he would schedule closure on 28-July-2021.
  5. Sectigo — Tim Callan noted the bug was scheduled to close on the 28th and that Sectigo would continue to monitor it until it closed.
Participants
Sectigo Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 100% similar
Sectigo: Incorrect JOI for federal credit unions
#1718771 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2023-02-22 · 100% similar
Sectigo: DCV Reuse after 825 days
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 98% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 96% similar
Sectigo: Failure to provide timely incident reports
#1620561 RESOLVED Self Reported Incident Opened 2020-03-06 · Closed 2023-02-22 · 95% similar
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates
#1715024 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-06-07 · Closed 2023-02-22 · 94% similar
Sectigo: Misspellings in stateOrProvince or localityName fields
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 93% similar
Sectigo: Subject field with unvalidated information included in certificates
#1645686 RESOLVED Certificate Misissuance Revocation Issue Opened 2020-06-14 · Closed 2023-02-22 · 93% similar
Sectigo: Lack of input validation in stateOrProvinceName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action