← Sectigo cases
Bugzilla #1800756 Delayed Revocation

Sectigo: Failure to revoke ECC certificates with non-DER encoded keyUsage within 5 days

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported an incident in which ECC certificates with a non-DER encoded keyUsage were not revoked within the usual 5-day window. Sectigo stated that during internal discussion of bug 1796803 it decided not to revoke the affected certificates due to the scale of impact and uncertainty about how reseller partners’ customers automate certificate handling. The CA reported that 322,161 unique certificate serial numbers were affected and that the last of these certificates would naturally expire on 2023-11-19. Sectigo also described that it considered mass revocation of this scale potentially harmful to the WebPKI and relying parties, and characterized the case as exceptional. In the thread, Sectigo indicated its initial writeup concluded the remediation and disclosure, and that it would watch the bug for questions or comments. Mozilla indicated it would close the bug unless additional issues or questions were raised, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:57 UTC Revised: 2026-06-16 18:57 UTC Confidence: 0.86 4 comments
Chronology
  1. Sectigo opened a CA Certificate Compliance bug describing a decision not to revoke affected ECC certificates within the usual 5-day window.
  2. Mozilla planned to close the bug unless additional issues or questions were raised.
Thread Activity
  1. Sectigo — Sectigo explained it became aware of the problem via internal discussion of bug 1796803 and decided not to revoke the affected certificates within the usual 5-day window, citing scale and potential ecosystem impact.
  2. Sectigo — Sectigo stated its initial writeup concluded the remediation and disclosure and that it would watch the bug for questions or comments.
  3. Sectigo — Sectigo said it had nothing further to add and believed the bug was ready to be closed.
  4. Mozilla representative — Mozilla said it would close the bug on or about Friday 2-Dec-2022 unless additional issues or questions were raised.
Participants
Sectigo Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1818073 RESOLVED Delayed Revocation Opened 2023-02-21 · Closed 2023-06-28 · 100% similar
Sectigo: Late revocation for incomplete Subject organizationName
#1813989 RESOLVED Delayed Revocation Opened 2023-01-31 · Closed 2023-05-04 · 89% similar
Sectigo: Incomplete Subject organizationName
#1635840 RESOLVED Delayed Revocation Opened 2020-05-06 · Closed 2023-02-22 · 88% similar
Sectigo: Failure to properly respond to a report of subscriber key compromise
#1698936 RESOLVED Delayed Revocation Opened 2021-03-16 · Closed 2023-02-22 · 88% similar
Sectigo: ZeroSSL: failure to revoke within 24 hours
#1639804 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 87% similar
Sectigo: Failure to revoke key-compromised certificate within 24 hours
#1639805 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 87% similar
Sectigo: Failure to revoke key-compromised certificates
#1665763 RESOLVED Delayed Revocation Opened 2020-09-17 · Closed 2023-02-22 · 87% similar
Sectigo: Failure to revoke within 5 days
#1625715 RESOLVED Delayed Revocation Opened 2020-03-29 · Closed 2023-02-22 · 81% similar
Sectigo: Failure to revoke certificate with previously-compromised key within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action