← Sectigo cases
Bugzilla #1878139 Incident

Sectigo: Failure to invalidate Email DCV Random Values after 30 days

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a compliance incident discovered through its ongoing code-review process: the Random Values used in its email-based domain control validation did not get invalidated after 30 days from creation. Sectigo stated it deployed a patch on February 1, 2024 to remediate the possibility that Random Values could be considered valid beyond the 30-day deadline, and it continued investigating whether any non-compliant certificate issuance occurred. In its incident report, Sectigo said 2,577 unexpired certificates issued between 2023-01-08 and 2024-02-01 were issued based on domain control validation that used a Random Value that should no longer have been considered valid. Sectigo also said it disabled reuse of the domain control validations associated with suspect certificates and scheduled a revocation event for February 7, 2024 at 14:00 UTC, after which it reported that all affected certificates had been revoked. After remediation, Sectigo noted that the remaining action item was expansion of its internal certificate audit process, including a check against Random Value age, and requested closing the bug once that final item was completed. Mozilla indicated it would close the bug on Wed 3-Apr-2024, and the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 18:59 UTC Confidence: 0.90 6 comments
Chronology
  1. Sectigo deployed a patch to ensure email-based DCV Random Values are not treated as valid beyond 30 days.
  2. Sectigo revoked all certificates identified as affected by the Random Value invalidation issue.
  3. Sectigo completed the final internal audit process action and requested closure of the bug.
Thread Activity
  1. Sectigo — Sectigo reported that it discovered Random Values for email-based DCV were not invalidated after 30 days, deployed a patch at 03:00 UTC, and planned to post a full incident report by Feb 9, 2024.
  2. Sectigo — Sectigo posted the incident report stating 2,577 unexpired certificates were issued using a Random Value that should no longer have been valid, and described the timeline and revocation plan.
  3. Sectigo — Sectigo said remediation was completed and asked Mozilla to set a next update for March 31 to track the final internal audit process item.
  4. Sectigo — Sectigo stated the final action item (including a check against Random Value age) was completed in its internal audit process and requested closing the bug.
  5. Mozilla representative — Mozilla agreed to close the bug on Wed 3-Apr-2024.
Participants
Sectigo Mozilla representative
Similar Local Cases
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 100% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1869056 RESOLVED Incident Opened 2023-12-08 · Closed 2024-02-02 · 98% similar
Sectigo: Inadequate vulnerability scanning and patching
#1891039 RESOLVED Incident Opened 2024-04-11 · Closed 2024-05-05 · 98% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 98% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1741777 RESOLVED Incident Opened 2021-11-18 · Closed 2023-02-22 · 95% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 94% similar
Sectigo: Incorrect OCSP responses
#1830088 RESOLVED Incident Opened 2023-04-26 · Closed 2024-03-27 · 93% similar
Sectigo: Late termination of privileged access to Certificate Systems
#2000277 RESOLVED Incident Opened 2025-11-14 · Closed 2025-12-19 · 90% similar
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action