← Sectigo cases
Bugzilla #1741777 Certificate Problem Report

Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature

RESOLVED FIXED Sectigo
AI Summary

Sectigo reported an issue regarding the direct signing of OCSP responses using root certificates that lack the digitalSignature Key Usage bit. This practice was deemed non-compliant with the Baseline Requirements (BRs) by major root programs, including Google Chrome. Sectigo acknowledged the need to update their affected root certificates and initiated a plan to replace them with new roots that include the required Key Usage. The resolution involved implementing delegated OCSP responders to ensure compliance and mitigate risks associated with the previous practice. The case was resolved with the deployment of new OCSP infrastructure in August 2022.

Model: gpt-4o-mini Generated: 2026-06-13 20:57 UTC Confidence: 0.90
Chronology
  1. Bug 1725039 reported regarding OCSP signing compliance.
  2. Sectigo acknowledged the issue and began planning for root certificate updates.
  3. Sectigo announced plans to implement delegated OCSP responders.
  4. Deployment of new OCSP infrastructure completed.
Participants
Tim Callan Rob Stradling Ryan Sleevi Ben Wilson
External References
Similar Local Cases
#1645686 RESOLVED Certificate Problem Report Opened 2020-06-14 · Closed 2023-02-22 · 73% similar
Sectigo: Lack of input validation in stateOrProvinceName
#1724458 RESOLVED Certificate Problem Report Opened 2021-08-06 · Closed 2023-02-22 · 73% similar
Sectigo: Mojibake in certificate Subject fields
#1698936 RESOLVED Certificate Problem Report Opened 2021-03-16 · Closed 2023-02-22 · 72% similar
Sectigo: ZeroSSL: failure to revoke within 24 hours
#1650845 RESOLVED Certificate Problem Report Opened 2020-07-06 · Closed 2024-06-30 · 71% similar
Sectigo: CPR response issues
#1715024 RESOLVED Certificate Problem Report Opened 2021-06-07 · Closed 2023-02-22 · 71% similar
Sectigo: Misspellings in stateOrProvince or localityName fields
#1718771 RESOLVED Certificate Problem Report Opened 2021-06-30 · Closed 2023-02-22 · 71% similar
Sectigo: DCV Reuse after 825 days
#1563579 RESOLVED Certificate Problem Report Opened 2019-07-04 · Closed 2023-02-22 · 71% similar
Sectigo: Failure to provide timely incident reports
#1725039 RESOLVED Certificate Problem Report Opened 2021-08-10 · Closed 2023-02-22 · 66% similar
Network Solutions: 2021 Audit Observation #1

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action