← Sectigo cases
Bugzilla #1823723 Subscriber Agreement Issue

Sectigo: Incomplete Subscriber Agreement provisions

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported that during its annual WebTrust audit, the auditor noted it was possible to order a certificate through at least one retail storefront without being presented with the Sectigo Certificate Subscriber Agreement. Sectigo investigated and determined that a bug in the retail storefront purchase paths could fail to present the Certificate Subscriber Agreement, even though customers were required to agree to the Terms of Use. Sectigo stated that the issue did not directly affect certificate issuance, but affected the legal agreement between CA and subscriber. Sectigo remediated the problem by updating its website so that acceptance of the Subscriber Agreement is included in the Terms of Use whenever a certificate is purchased, and by updating the Terms of Use so the required obligations and warranties apply to all active certificate subscribers. Sectigo also concluded a comprehensive compliance review and reported that it found no further cases of the problem. The bug was marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 18:58 UTC Confidence: 0.86 4 comments
Chronology
  1. Sectigo demonstrated the OV certificate order and issuance process to its auditor.
  2. Sectigo received auditor questions about when the Subscriber Agreement is agreed during OV certificate ordering.
  3. Sectigo’s WIR team was informed of the auditor finding and began investigating.
  4. Sectigo deployed website changes to resolve the missing Subscriber Agreement presentation in affected purchase paths.
  5. Sectigo reported completion of a comprehensive compliance review with no further cases found.
Thread Activity
  1. Sectigo — Martijn Katerbarg described how an annual WebTrust audit found that a retail storefront purchase path could omit presenting the Certificate Subscriber Agreement, and detailed Sectigo’s investigation and remediation steps.
  2. Sectigo — Martijn Katerbarg stated the incident was remediated and that a comprehensive compliance review found no further cases.
  3. Mozilla representative — Ben Wilson indicated he would close the bug on or about 5-Apr-2023 unless additional discussion was needed.
  4. Sectigo — Martijn Katerbarg agreed that, unless other comments were added, the incident should be considered resolved.
Participants
Sectigo Mozilla representative
External References
Similar Local Cases
#1860299 RESOLVED Certificate Misissuance Opened 2023-10-20 · Closed 2023-12-02 · 62% similar
Sectigo: SMIME issuance with insufficient validation of mailbox authorization or control
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 62% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 61% similar
Sectigo: Incorrect JOI for federal credit unions
#1853987 RESOLVED Certificate Misissuance Opened 2023-09-19 · Closed 2023-10-12 · 61% similar
Sectigo: S/MIME certificates with (null) string value in subject attributes
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 61% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 61% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1724458 RESOLVED Ca Certificate Compliance Opened 2021-08-06 · Closed 2023-02-22 · 61% similar
Sectigo: Mojibake in certificate Subject fields
#1756847 RESOLVED Certificate Misissuance Opened 2022-02-23 · Closed 2023-02-22 · 60% similar
Sectigo: SC45 DCV Reuse Error

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action