Sectigo: CRL validity beyond CPS allowed value
Sectigo reported that its CRL validity periods did not match what its CPS allowed. The CA said it became aware of the issue after monitoring external Mozilla-related bugs and then reviewing its own CRLs against its CPS and Baseline Requirements. Sectigo found a mismatch in CRL validity timing (described as a “plus-second” behavior) and concluded that its CRLs were non-compliant with its CPS. Sectigo published a CPS update on October 5, extending the time at which it would issue a new CRL to fix the CRL mismatch. The CA stated that this matter did not result in certificate misissuance and that its CRLs were fully compliant in validity time with its current CPS. Sectigo also said it would continue monitoring the bug and keep a separate ticket open to fix the “plus-second” behavior to reduce the likelihood of future problems. The bug is marked RESOLVED with resolution FIXED.
- Google Trust Services opened bug 1731164, which Sectigo monitored as part of its incident response process.
- QuoVadis opened bug 1733000, prompting Sectigo to review its own CPS and CRL behavior.
- Sectigo published a CPS update to extend the time at which it would issue a new CRL, fixing the CRL validity mismatch with its CPS.
- Sectigo proposed closure of the bug and Mozilla scheduled it for closure.
- Sectigo — Sectigo explained that it discovered a mismatch between its CPS and actual CRL validity periods after reviewing its CRLs, and said it published a CPS update on October 5 to fix the mismatch.
- Sectigo — Sectigo stated it had provided all necessary information and would continue monitoring the bug for questions or comments.
- Sectigo — Sectigo proposed closure of the bug because no additional questions appeared.
- Mozilla representative — Mozilla said it would schedule the bug to be closed on 3-Nov-2021.
- Sectigo — Sectigo noted the bug was due to be closed and said it would continue monitoring until closure.