← Sectigo cases
Bugzilla #1796803 Certificate Problem Report

Sectigo: Issuance of ECC leaf certificates with non-DER encoded keyUsage

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified an issue with ECC leaf certificates that contained an incorrect number of unused bits in their keyUsage BITSTRINGs. Upon discovery, they promptly upgraded their preissuance linting system to prevent further misissuance. A comprehensive incident report is expected, detailing the scope of the problem and the measures taken to rectify it. The affected certificates were not revoked within the usual timeframe, leading to a separate bug being opened for further explanation.

Model: gpt-4o-mini Generated: 2026-06-13 20:57 UTC Confidence: 0.95
Chronology
  1. Sectigo discovers issue with ECC leaf certificates.
  2. Sectigo accelerates upgrade of preissuance linting system.
  3. Sectigo provides updates on affected certificates.
  4. Discussion on closing the bug due to lack of further questions.
Participants
Rob Stradling Ben Wilson Ryan Dickson
Related Bugzilla IDs Mentioned
Similar Local Cases
#1800756 RESOLVED Certificate Problem Report Opened 2022-11-15 · Closed 2023-02-22 · 67% similar
Sectigo: Failure to revoke ECC certificates with non-DER encoded keyUsage within 5 days
#1741777 RESOLVED Certificate Problem Report Opened 2021-11-18 · Closed 2023-02-22 · 63% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1912225 RESOLVED Certificate Problem Report Opened 2024-08-08 · Closed 2024-09-26 · 61% similar
Sectigo: HTML encoded characters in subject attribute values
#1653504 RESOLVED Certificate Problem Report Opened 2020-07-17 · Closed 2023-02-22 · 60% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8
#1853987 RESOLVED Certificate Problem Report Opened 2023-09-19 · Closed 2023-10-12 · 60% similar
Sectigo: S/MIME certificates with (null) string value in subject attributes
#1793787 RESOLVED Certificate Problem Report Opened 2022-10-05 · Closed 2023-02-22 · 59% similar
Sectigo: Non-existent hostname in CDP and AIA URLs
#1897538 RESOLVED Certificate Problem Report Opened 2024-05-17 · Closed 2024-06-14 · 59% similar
Sectigo: Incorrectly included registrationStateOrProvince in PSD-based cabfOrganizationIdentifier extension
#1902748 RESOLVED Certificate Problem Report Opened 2024-06-14 · Closed 2024-08-28 · 59% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action