← Sectigo cases
Bugzilla #1793787 Ca Certificate Compliance Self Reported Incident Incident Repository Issue Ccadb Disclosure Issue

Sectigo disclosed non-existent hostname in CDP and AIA URLs for newly issued subordinate CA certificates

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported that it discovered a problem while working on a crt.sh feature that tracks CCADB CRL disclosures, when Rob Stradling noticed one of its CRLs had a hostname that did not exist. The bug describes newly issued subordinate CA certificates whose OCSP, CRL, and caIssuer hostnames had not been created in DNS. Sectigo said it disabled the subordinate CAs until the certificates were disclosed in CCADB, then re-enabled them and later added the required DNS CNAME records. Sectigo stated that no further certificates were issued between discovering and fixing the root cause, and that two certificates issued on 2022-09-21 were affected. Sectigo later said remediation was complete and asked whether the bug could be closed; Mozilla indicated it would close the bug unless there were further questions.

Model: gpt-5.4-mini Generated: 2026-06-13 20:57 UTC Revised: 2026-07-23 19:25 UTC Confidence: 0.97 4 comments
Chronology
  1. Sectigo issued new subordinate CA certificates and initially disabled them until CCADB disclosure was possible.
  2. Sectigo issued two leaf certificates under the new subordinate CA certificates with non-existent caIssuer, OCSP, and CRL hostnames.
  3. Sectigo added the required DNS CNAME records for the missing hostnames.
  4. Sectigo said remediation of the incident was complete.
Thread Activity
  1. Sectigo — Sectigo opened the bug and explained that it had discovered the non-existent hostname issue while working on a crt.sh feature.
  2. Sectigo — Sectigo said the remediation steps were complete and it was monitoring the bug for comments.
  3. Sectigo — Sectigo asked whether the bug could be closed.
  4. Mozilla representative — Mozilla said it would close the bug on or about 2022-10-21 unless there were additional questions or issues.
Participants
Sectigo Mozilla representative
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 96% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 96% similar
Sectigo: Incorrect JOI for federal credit unions
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 95% similar
Sectigo: Incorrect OCSP responses
#1597950 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-20 · Closed 2023-02-22 · 88% similar
Sectigo: CCADB failed ALV - Ensured Root CA
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 87% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 87% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1891039 RESOLVED Incident Opened 2024-04-11 · Closed 2024-05-05 · 87% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1945197 RESOLVED Self Reported Incident Audit Delay Opened 2025-01-31 · Closed 2025-02-28 · 87% similar
Sectigo: Late receipt and disclosure to CCADB of ETSI audit letters

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action