← Sectigo cases
Bugzilla #1741777 Incident

Sectigo OCSP responses signed by roots lacking digitalSignature KU; Sectigo moved to delegated responders

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported that it had been directly signing OCSP responses with root certificates that predated the Baseline Requirements and did not have the digitalSignature Key Usage bit set. The issue came to Sectigo’s attention after discussion in bug 1725039 and a Chrome Root Authority Program position that this practice was noncompliant. Sectigo initially planned to replace the affected roots with new versions, but after further discussion it changed course and said it would fully resolve the issue by implementing delegated OCSP responders for the affected root CAs. Sectigo then worked through implementation and deployment of the new OCSP infrastructure, including new responder certificates and phased rollout. Sectigo later reported that it completed deployment and migration on 2022-08-25 and said this completed its remediation of the incident. The bug was then closed as RESOLVED/FIXED.

Model: gpt-5.4-mini Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:55 UTC Confidence: 0.96 33 comments
Chronology
  1. Bug 1725039 raised the issue of direct OCSP signing by a root certificate lacking digitalSignature KU.
  2. Sectigo disclosed that it had been directly signing OCSP responses with affected roots and opened this bug.
  3. Sectigo said it would not issue replacement roots and would instead implement delegated OCSP responders.
  4. Sectigo experienced OCSP response validation errors during rollout of the new delegated OCSP service.
  5. Sectigo completed deployment of and migration to its new OCSP infrastructure.
  6. Mozilla indicated the bug would be closed.
Thread Activity
  1. Sectigo — Sectigo explained how it learned of the issue from bug 1725039 and disclosed that it had been directly signing OCSP responses with roots lacking digitalSignature KU.
  2. Sectigo — Sectigo clarified that its initial plan was to create replacement root certificates with the digitalSignature bit added.
  3. Community commenter — Ryan Sleevi questioned the compatibility impact of the proposed root replacement approach and asked why delegated responders were not being used.
  4. Sectigo — Sectigo said it was waiting for broader discussion and asked for more time before resuming or reconsidering its root replacement plan.
  5. Sectigo — Sectigo said it would announce an updated remediation plan in early January after Chrome confirmed its view.
  6. Sectigo — Sectigo said it would fully and unambiguously resolve the issue by implementing delegated OCSP responders and would not issue the replacement roots.
  7. Sectigo — Sectigo said it was implementing delegated responder support and did not yet have a firm release target.
  8. Sectigo — Sectigo said it had issued new certificates for signing OCSP responses.
  9. Sectigo — Sectigo described a July 6-7 OCSP slowdown and validation errors caused by rollout of the new delegated OCSP service.
  10. Sectigo — Sectigo provided a detailed incident writeup describing the OCSP backlog and hotfixes during rollout.
  11. Sectigo — Sectigo said it completed deployment and migration to the new OCSP infrastructure on 2022-08-25 and considered the incident remediated.
  12. Sectigo — Sectigo asked to close the bug, and Mozilla replied that it intended to close it on or about 2022-09-09.
Participants
Sectigo Community commenter Mozilla representative
Similar Local Cases
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 100% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 97% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1869056 RESOLVED Incident Opened 2023-12-08 · Closed 2024-02-02 · 95% similar
Sectigo: Inadequate vulnerability scanning and patching
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 95% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1891039 RESOLVED Incident Opened 2024-04-11 · Closed 2024-05-05 · 95% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1593776 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-04 · Closed 2023-02-22 · 95% similar
Sectigo: invalid subject:organizationalUnitName on DV certificates
#1597950 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-20 · Closed 2023-02-22 · 95% similar
Sectigo: CCADB failed ALV - Ensured Root CA
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 94% similar
Sectigo: Incorrect OCSP responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action