Sectigo: 2020 failure to respond to CPRs discovered
Sectigo reported a compliance issue discovered during its WebTrust audit: for one of 45 Certificate Problem Reports selected for testing, Sectigo did not provide a preliminary report to the subscriber and the entity that filed the Certificate Problem Report, and Sectigo could not provide evidence that an investigation had started within 24 hours of receiving the report. Sectigo stated that revocation did occur less than 48 hours from the initial report, and that the flaw may have been in recording evidence of its activity. Sectigo said the issue was previously unreported and that it was reporting it now after realizing it during the audit evidence-gathering process. Sectigo explained that prior to December 2020 it had a manual process for accepting and dispositioning reports to its SSL abuse email address, and that it had been vulnerable to error; it also described that it was specifying and developing an automated response system for inbound abuse reports. Sectigo stated that it remediated the issue by using an automated response mechanism for inbound abuse reports, and that it had released this system into production on December 8, 2020. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it would be scheduled for closure on July 28, 2021.
- Bug 1648717 was opened to report errors in responses to inbound problem reports.
- A revocation requester emailed s**********e@sectigo.com regarding a Sectigo-issued SSL certificate used in a phishing campaign.
- The certificate was revoked and a support email was sent advising of the revocation.
- Sectigo released an automated response to SSL abuse reports into production.
- Sectigo discovered the reporting flaw during its WebTrust audit evidence gathering.
- Sectigo compliance began drafting the post after realizing the error remained unreported.
- Mozilla scheduled the bug for closure.
- Sectigo — Tim Callan described how Sectigo became aware of the issue during its WebTrust audit, provided a timeline, and stated remediation via an automated response mechanism released on December 8, 2020.
- Sectigo — Tim Callan asked whether there were any questions.
- Sectigo — Tim Callan said there was nothing to add and that the bug was ready for closing.
- Mozilla representative — Ben Wilson said he would schedule closure on 28-July-2021.
- Sectigo — Tim Callan noted the bug was scheduled to close on the 28th and that Sectigo would continue to monitor it until it closed.