← Sectigo cases
Bugzilla #1735761 Technical Compliance

Sectigo: CRL validity beyond CPS allowed value

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified a mismatch between their Certificate Revocation Lists (CRLs) and their Certificate Practice Statement (CPS) during a review prompted by external bug reports. Although their CRLs had a 'plus-second' behavior, they concluded it did not violate Baseline Requirements due to a 7-day limit. Following the review, they updated their CPS to align with their CRL practices. No certificate misissuance occurred as a result of this issue, and measures have been implemented to prevent future discrepancies.

Model: gpt-4o-mini Generated: 2026-06-13 20:57 UTC Confidence: 0.95
Chronology
  1. Google Trust Services opens bug 1731164.
  2. Review concludes no BR violation; ticket opened for plus-second behavior.
  3. CPS updated to fix CRL mismatch.
Participants
Martijn Katerbarg Tim Callan B. Wilson
External References
Similar Local Cases
#1830088 RESOLVED Technical Compliance Opened 2023-04-26 · Closed 2024-03-27 · 58% similar
Sectigo: Late termination of privileged access to Certificate Systems
#1972547 RESOLVED Technical Compliance Opened 2025-06-17 · Closed 2025-07-16 · 57% similar
Sectigo: Lack of technical controls for multiparty control access to Secure Zone
#1699756 RESOLVED Technical Compliance Opened 2021-03-19 · Closed 2022-11-14 · 54% similar
Sectigo: Reseller ZeroSSL and Private Key Generation
#1819422 RESOLVED Technical Compliance Opened 2023-02-28 · Closed 2023-03-24 · 47% similar
Certainly: CRL Issuing Distribution Point Mismatch in CCADB
#1738191 RESOLVED Technical Compliance Opened 2021-10-28 · Closed 2023-02-22 · 46% similar
GDCA: CRL validity period exceeds allowed value by one second
#1731164 RESOLVED Technical Compliance Opened 2021-09-16 · Closed 2023-02-22 · 45% similar
Google Trust Services: CRL validity period set to expected value plus one second
#1732745 RESOLVED Technical Compliance Opened 2021-09-27 · Closed 2023-02-22 · 45% similar
Certainly: Root CRL validity period exceeds maximum by one second
#1737057 RESOLVED Technical Compliance Opened 2021-10-21 · Closed 2023-02-22 · 43% similar
Entrust: CRLs and OCSP responses not issued as specified in the CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action