← Sectigo cases
Bugzilla #1735761 Delayed Revocation

Sectigo: CRL validity beyond CPS allowed value

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported that its CRL validity periods did not match what its CPS allowed. The CA said it became aware of the issue after monitoring external Mozilla-related bugs and then reviewing its own CRLs against its CPS and Baseline Requirements. Sectigo found a mismatch in CRL validity timing (described as a “plus-second” behavior) and concluded that its CRLs were non-compliant with its CPS. Sectigo published a CPS update on October 5, extending the time at which it would issue a new CRL to fix the CRL mismatch. The CA stated that this matter did not result in certificate misissuance and that its CRLs were fully compliant in validity time with its current CPS. Sectigo also said it would continue monitoring the bug and keep a separate ticket open to fix the “plus-second” behavior to reduce the likelihood of future problems. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:55 UTC Confidence: 0.50 5 comments
Chronology
  1. Google Trust Services opened bug 1731164, which Sectigo monitored as part of its incident response process.
  2. QuoVadis opened bug 1733000, prompting Sectigo to review its own CPS and CRL behavior.
  3. Sectigo published a CPS update to extend the time at which it would issue a new CRL, fixing the CRL validity mismatch with its CPS.
  4. Sectigo proposed closure of the bug and Mozilla scheduled it for closure.
Thread Activity
  1. Sectigo — Sectigo explained that it discovered a mismatch between its CPS and actual CRL validity periods after reviewing its CRLs, and said it published a CPS update on October 5 to fix the mismatch.
  2. Sectigo — Sectigo stated it had provided all necessary information and would continue monitoring the bug for questions or comments.
  3. Sectigo — Sectigo proposed closure of the bug because no additional questions appeared.
  4. Mozilla representative — Mozilla said it would schedule the bug to be closed on 3-Nov-2021.
  5. Sectigo — Sectigo noted the bug was due to be closed and said it would continue monitoring until closure.
Participants
Sectigo Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1800756 RESOLVED Delayed Revocation Opened 2022-11-15 · Closed 2023-02-22 · 61% similar
Sectigo: Failure to revoke ECC certificates with non-DER encoded keyUsage within 5 days
#1818073 RESOLVED Delayed Revocation Opened 2023-02-21 · Closed 2023-06-28 · 61% similar
Sectigo: Late revocation for incomplete Subject organizationName
#1908690 RESOLVED Delayed Revocation Opened 2024-07-18 · Closed 2024-08-23 · 60% similar
Sectigo: Temporary unavailability for subset of CRLs
#1665763 RESOLVED Delayed Revocation Opened 2020-09-17 · Closed 2023-02-22 · 59% similar
Sectigo: Failure to revoke within 5 days
#1698936 RESOLVED Delayed Revocation Opened 2021-03-16 · Closed 2023-02-22 · 58% similar
Sectigo: ZeroSSL: failure to revoke within 24 hours
#1813989 RESOLVED Delayed Revocation Opened 2023-01-31 · Closed 2023-05-04 · 53% similar
Sectigo: Incomplete Subject organizationName
#1756847 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 51% similar
Sectigo: SC45 DCV Reuse Error
#2031087 RESOLVED Delayed Revocation Opened 2026-04-11 · Closed 2026-06-06 · 51% similar
Sectigo: Partial OCSP response publication delay for newly issued certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action