← Sectigo cases
Bugzilla #1830088 Incident

Sectigo: Late termination of privileged access to Certificate Systems

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Sectigo's late termination of privileged access to its Certificate Systems for an employee, identified as Employee X. The issue was discovered during a WebTrust audit update call, revealing that the termination notification was sent outside the required timeframe due to a weekend delay. Sectigo conducted an internal investigation, confirmed the discrepancy, and updated its termination procedures to ensure timely account access termination in the future. Although the case was initially resolved, a recurrence of the issue prompted Sectigo to reopen the bug for further monitoring and improvements to their offboarding processes. As of the latest updates, Sectigo has completed phases of an overhaul to enhance their internal procedures.

Model: gpt-4o-mini Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 18:58 UTC Confidence: 0.85 13 comments
Chronology
  1. Sectigo discovered a discrepancy in the termination of privileged access during an audit.
  2. Sectigo completed the second phase of their overhaul of internal processes related to account terminations.
Thread Activity
  1. Sectigo — Sectigo reported the late termination of access for Employee X discovered during an audit.
  2. Sectigo — Sectigo confirmed completion of remediation and investigation, requesting to close the bug.
  3. Sectigo — Sectigo reopened the bug due to a recurrence of the incident.
  4. Sectigo — Sectigo indicated that further automation has been added to their offboarding process.
Participants
Sectigo Mozilla representative
External References
Similar Local Cases
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 95% similar
Sectigo: Incorrect OCSP responses
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 95% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1869056 RESOLVED Incident Opened 2023-12-08 · Closed 2024-02-02 · 94% similar
Sectigo: Inadequate vulnerability scanning and patching
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 94% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1741777 RESOLVED Incident Opened 2021-11-18 · Closed 2023-02-22 · 93% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 93% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1891039 RESOLVED Incident Opened 2024-04-11 · Closed 2024-05-05 · 93% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1972547 RESOLVED Incident Policy Document Issue Opened 2025-06-17 · Closed 2025-07-16 · 89% similar
Sectigo: Lack of technical controls for multiparty control access to Secure Zone

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action