← Sectigo cases
Bugzilla #1830088 Technical Compliance

Sectigo: Late termination of privileged access to Certificate Systems

RESOLVED FIXED Sectigo
AI Summary

Sectigo identified a delay in terminating privileged access for an employee, which was reported during a WebTrust audit. The termination notice was sent after the employee's contract expired, violating the 24-hour requirement set by the NSRs. Following an internal investigation, Sectigo updated its termination procedures and automated parts of its audit checks to ensure compliance. Despite these efforts, a recurrence of the issue was noted, prompting further discussions on restructuring the offboarding process. Ongoing improvements are being made to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 20:56 UTC Confidence: 0.90
Chronology
  1. Employee X's contract set to expire.
  2. Discrepancy found in account termination during audit.
  3. Remediation and investigation completed.
  4. Recurrence of incident noted.
  5. Phase 1 of overhaul completed.
  6. Phase 2 of overhaul completed.
Participants
Martijn Katerbarg Ben Wilson
External References
Similar Local Cases
#1735761 RESOLVED Technical Compliance Opened 2021-10-14 · Closed 2023-02-22 · 58% similar
Sectigo: CRL validity beyond CPS allowed value
#1972547 RESOLVED Technical Compliance Opened 2025-06-17 · Closed 2025-07-16 · 58% similar
Sectigo: Lack of technical controls for multiparty control access to Secure Zone
#1699756 RESOLVED Technical Compliance Opened 2021-03-19 · Closed 2022-11-14 · 55% similar
Sectigo: Reseller ZeroSSL and Private Key Generation
#1771727 RESOLVED Technical Compliance Opened 2022-05-30 · Closed 2023-02-22 · 49% similar
Firmaprofesional: 2022 - Define Device Obsolescence Process
#1716902 RESOLVED Technical Compliance Opened 2021-06-17 · Closed 2023-02-22 · 48% similar
E-Tugra: Forbidden Domain Validation Method 3.2.2.4.6
#1718680 RESOLVED Technical Compliance Opened 2021-06-29 · Closed 2023-02-22 · 47% similar
Asseco DS / Certum: Forward dating certificates (notBefore in the future)
#1684112 RESOLVED Technical Compliance Opened 2020-12-23 · Closed 2023-02-22 · 47% similar
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
#1832338 RESOLVED Technical Compliance Opened 2023-05-10 · Closed 2023-06-08 · 46% similar
Firmaprofesional: 2023 - Ensure Timestamp service Logs Integrity

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action