← Sectigo cases
Bugzilla #1796803 Self Reported Incident

Sectigo: Issuance of ECC leaf certificates with non-DER encoded keyUsage

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo discovered that some ECC leaf certificates issued by its CA platform contained an incorrect number of unused bits in their keyUsage BITSTRINGs. This issue was identified on October 20, 2022, through a linting tool. To mitigate further misissuance, Sectigo upgraded its preissuance linting system and deployed a bugfix the same day. They also initiated a script to identify all affected certificates, which ultimately identified 322,161 unique serial numbers. Sectigo decided not to revoke the affected certificates within the usual timeframe and opened a separate bug to explain this decision. The case has since been resolved.

Model: gpt-4o-mini Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:57 UTC Confidence: 0.90 16 comments
Chronology
  1. Sectigo discovered the issue with ECC leaf certificates.
  2. Sectigo deployed a bugfix to prevent further misissuance.
  3. Sectigo decided not to revoke the affected certificates.
Thread Activity
  1. Sectigo — We discovered that some ECC leaf certificates contain an incorrect number of unused bits in their keyUsage BITSTRINGs.
  2. Mozilla representative — Thanks, Rob, for your rapid response. This is very noteworthy.
  3. Sectigo — We propose that this bug should now be closed.
  4. Mozilla representative — I will close this on or about Monday, 28-Nov-2022, unless there are additional questions.
Participants
Sectigo Mozilla representative Google representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 100% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1718771 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2023-02-22 · 98% similar
Sectigo: DCV Reuse after 825 days
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 97% similar
Sectigo: Subject field with unvalidated information included in certificates
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 95% similar
Sectigo: Incorrect JOI for federal credit unions
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 94% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1945197 RESOLVED Self Reported Incident Audit Delay Opened 2025-01-31 · Closed 2025-02-28 · 93% similar
Sectigo: Late receipt and disclosure to CCADB of ETSI audit letters
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 92% similar
Sectigo: Failure to provide timely incident reports
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 88% similar
Sectigo: EV SSL Certificates with incorrect subject details.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action