← Sectigo cases
Bugzilla #1823723 Policy Compliance

Sectigo: Incomplete Subscriber Agreement provisions

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified an issue during an annual WebTrust Audit where customers could order certificates without being presented with the Sectigo Certificate Subscriber Agreement. This was due to a bug in a third-party e-commerce system, WHMCS, which failed to present the agreement in certain purchase paths. The issue has been remediated by updating the Terms of Use to include acceptance of the Subscriber Agreement. A comprehensive compliance review confirmed no further cases of the problem.

Model: gpt-4o-mini Generated: 2026-06-13 20:56 UTC Confidence: 1.00
Chronology
  1. Demo of the order and issuance process conducted with auditor.
  2. Auditor inquires about the Subscriber Agreement presentation.
  3. WIR team informed of the auditor's finding.
  4. WIR team confirms the issue and discusses findings.
  5. Legal team added to ongoing discussions.
  6. Changes deployed to website to resolve the issue.
  7. Compliance review concluded with no further issues.
  8. Case closed as resolved.
Participants
Martijn Katerbarg Ben Wilson
External References
Similar Local Cases
#1942651 RESOLVED Policy Compliance Opened 2025-01-20 · Closed 2025-02-14 · 55% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1545208 RESOLVED Policy Compliance Opened 2019-04-17 · Closed 2023-02-22 · 50% similar
Sectigo: Missing Changelog in CPS
#1769222 RESOLVED Policy Compliance Opened 2022-05-13 · Closed 2024-06-30 · 48% similar
SECOM: Failed an annual CPS update of Cybertrust Japan (CTJ)
#1625715 RESOLVED Policy Compliance Opened 2020-03-29 · Closed 2023-02-22 · 48% similar
Sectigo: Failure to revoke certificate with previously-compromised key within 24 hours
#1959721 RESOLVED Policy Compliance Opened 2025-04-10 · Closed 2025-06-12 · 47% similar
Lawtrust: The S/MIME CA’s policy identifiers did not align with the CA/Browser Forum Requirements.
#1907568 RESOLVED Policy Compliance Opened 2024-07-12 · Closed 2024-09-06 · 47% similar
NETLOCK: CPS 1.5.2. problem and contact information update
#1738778 RESOLVED Policy Compliance Opened 2021-11-01 · Closed 2023-02-22 · 47% similar
TWCA: Policy OID not set to indicate the assurance level to the issued certs
#1942651 RESOLVED Policy Compliance Opened 2025-01-20 · Closed 2025-02-14 · 46% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action