← Sectigo cases
Bugzilla #1800756 Certificate Problem Report

Sectigo: Failure to revoke ECC certificates with non-DER encoded keyUsage within 5 days

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified a failure to revoke a significant number of ECC certificates that contained non-DER encoded keyUsage within the mandated 5-day period. After assessing the impact, including potential disruptions to a large number of subscribers and relying parties, Sectigo decided against mass revocation. The affected certificates, totaling 322,161, will naturally expire on November 19, 2023. This decision was based on the belief that the issue did not pose a security risk and had not caused compatibility problems in practice.

Model: gpt-4o-mini Generated: 2026-06-13 20:57 UTC Confidence: 0.90
Chronology
  1. Bug 1796803 created, leading to internal discussions.
  2. Completion of the script identifying affected certificates.
  3. Discussion during WebPKI Incident Response call about the incident.
  4. Initial writeup concludes remediation and disclosure.
  5. Final comments indicate readiness to close the bug.
Participants
Martijn Katerbarg Rob Stradling Ben Wilson
Related Bugzilla IDs Mentioned
Similar Local Cases
#1796803 RESOLVED Certificate Problem Report Opened 2022-10-21 · Closed 2023-02-22 · 67% similar
Sectigo: Issuance of ECC leaf certificates with non-DER encoded keyUsage
#1912225 RESOLVED Certificate Problem Report Opened 2024-08-08 · Closed 2024-09-26 · 66% similar
Sectigo: HTML encoded characters in subject attribute values
#1908690 RESOLVED Certificate Problem Report Opened 2024-07-18 · Closed 2024-08-23 · 65% similar
Sectigo: Temporary unavailability for subset of CRLs
#1741777 RESOLVED Certificate Problem Report Opened 2021-11-18 · Closed 2023-02-22 · 64% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1793787 RESOLVED Certificate Problem Report Opened 2022-10-05 · Closed 2023-02-22 · 64% similar
Sectigo: Non-existent hostname in CDP and AIA URLs
#1853987 RESOLVED Certificate Problem Report Opened 2023-09-19 · Closed 2023-10-12 · 64% similar
Sectigo: S/MIME certificates with (null) string value in subject attributes
#1891039 RESOLVED Certificate Problem Report Opened 2024-04-11 · Closed 2024-05-05 · 64% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1902748 RESOLVED Certificate Problem Report Opened 2024-06-14 · Closed 2024-08-28 · 64% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action