Sectigo: Failure to revoke ECC certificates with non-DER encoded keyUsage within 5 days
Sectigo reported an incident in which ECC certificates with a non-DER encoded keyUsage were not revoked within the usual 5-day window. Sectigo stated that during internal discussion of bug 1796803 it decided not to revoke the affected certificates due to the scale of impact and uncertainty about how reseller partners’ customers automate certificate handling. The CA reported that 322,161 unique certificate serial numbers were affected and that the last of these certificates would naturally expire on 2023-11-19. Sectigo also described that it considered mass revocation of this scale potentially harmful to the WebPKI and relying parties, and characterized the case as exceptional. In the thread, Sectigo indicated its initial writeup concluded the remediation and disclosure, and that it would watch the bug for questions or comments. Mozilla indicated it would close the bug unless additional issues or questions were raised, and the bug is marked RESOLVED with resolution FIXED.
- Sectigo opened a CA Certificate Compliance bug describing a decision not to revoke affected ECC certificates within the usual 5-day window.
- Mozilla planned to close the bug unless additional issues or questions were raised.
- Sectigo — Sectigo explained it became aware of the problem via internal discussion of bug 1796803 and decided not to revoke the affected certificates within the usual 5-day window, citing scale and potential ecosystem impact.
- Sectigo — Sectigo stated its initial writeup concluded the remediation and disclosure and that it would watch the bug for questions or comments.
- Sectigo — Sectigo said it had nothing further to add and believed the bug was ready to be closed.
- Mozilla representative — Mozilla said it would close the bug on or about Friday 2-Dec-2022 unless additional issues or questions were raised.