← Sectigo cases
Bugzilla #1876775 Incident

Sectigo: Wrong usage of LEI records for the issuance of S/MIME Certificates

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported an incident discovered through an internal pre-validation records audit involving the use of LEI records for S/MIME certificate validation. The audit found that, in some cases, the requirements in the S/MIME Baseline Requirements were not met, specifically that LEI validation details were not properly verified (including RegistrationStatus, EntityStatus, and ValidationSources). Sectigo stated the impact as 4,137 S/MIME certificates issued to 12 legal entities with incorrect validation records, and noted that 1,522 of those had already been revoked via customer requests. After confirming 12 pre-validation records as invalid, Sectigo initiated internal revocation for the affected certificates that had not yet been revoked, with revocation scheduled for January 26 and completed by 22:00 UTC. Sectigo also reported that it deployed a new pre-issuance linter in its issuance system to prevent recurrence, after QA testing and deployment. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it would close the bug unless further questions or comments were raised.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 18:59 UTC Confidence: 0.90 6 comments
Chronology
  1. Sectigo’s internal pre-validation records audit raised suspicion about LEI-based S/MIME validation records not meeting S/MIME Baseline Requirements.
  2. Sectigo completed revocation of all affected, not previously revoked S/MIME certificates by 22:00 UTC.
  3. Sectigo deployed a new pre-issuance linter to prevent recurrence of the LEI validation issue.
Thread Activity
  1. Sectigo — Created the incident report attachment describing 4,137 affected S/MIME certificates, invalid pre-validation records, and planned revocation and remediation actions.
  2. Sectigo — Confirmed revocation of all affected and previously not yet revoked certificates was completed by 22:00 UTC on January 26.
  3. Sectigo — Reported the new pre-issuance linter code passed initial code review and was with QA.
  4. Sectigo — Reported minor linter code changes after QA feedback and that QA sign-off was pending.
  5. Sectigo — Reported QA testing passed and the new pre-issuance linter was deployed on February 18; requested closing the bug.
  6. Mozilla representative — Indicated Mozilla would close the bug on or about 26-Feb-2024 unless there were questions or comments for Sectigo.
Participants
Sectigo Mozilla representative
External References
Similar Local Cases
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 100% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1869056 RESOLVED Incident Opened 2023-12-08 · Closed 2024-02-02 · 99% similar
Sectigo: Inadequate vulnerability scanning and patching
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 98% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1741777 RESOLVED Incident Opened 2021-11-18 · Closed 2023-02-22 · 97% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1891039 RESOLVED Incident Opened 2024-04-11 · Closed 2024-05-05 · 97% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 96% similar
Sectigo: Incorrect OCSP responses
#1830088 RESOLVED Incident Opened 2023-04-26 · Closed 2024-03-27 · 94% similar
Sectigo: Late termination of privileged access to Certificate Systems
#2000277 RESOLVED Incident Opened 2025-11-14 · Closed 2025-12-19 · 90% similar
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action