Sectigo: Premature disabling of CRL generation for an inactive CA
Sectigo reported a compliance incident after disabling CRL generation for several expired CAs in March 2024. The incident was triggered when Sectigo noticed that one disabled CRL belonged to an expired S/MIME Root CA that also had two unexpired cross-certificates issued by a currently trusted root, meaning the CRL disablement affected certificates that were still unexpired. Sectigo stated it would resolve the matter by revoking the two cross-certified subordinate CA certificates. Sectigo’s incident report describes how a pre-release CRL Monitor began logging failures in March 2024, but alerting was not enabled, and the issue was later manually reviewed and escalated in April. Sectigo received Policy Authority authorization and marked the two affected CA certificates as revoked in its database, preparing for an offline revocation ceremony scheduled for April 17, 2024. In later comments, Sectigo requested the bug be marked resolved, and Mozilla asked whether any questions remained before closure; a reviewer also asked whether an action item was completed, and Sectigo responded that the PA Policy update had been completed on April 23, 2024 and acknowledged an oversight in posting the reviewed update to the bug.
- Sectigo disabled CRL generation for several expired CAs.
- Sectigo noticed that a disabled CRL belonged to an expired S/MIME root with unexpired cross-certificates, identifying a compliance incident.
- Sectigo received Policy Authority authorization to revoke the two affected CA certificates.
- Sectigo marked the two affected CA certificates as revoked in its database and prepared for the offline revocation ceremony.
- Sectigo completed the offline revocation ceremony for the affected CA certificates.
- Sectigo requested the bug be marked resolved and Mozilla indicated it would close if no issues remained.
- Sectigo — Sectigo reported that disabling CRL generation for expired CAs caused a compliance incident because an expired S/MIME Root CA’s CRL was disabled while two unexpired cross-certificates existed, and said it would revoke those cross-certificates.
- Sectigo — Sectigo posted a fuller incident report with impact, timeline, and details of how the CRL Monitor failures were detected and escalated.
- Sectigo — Sectigo requested marking the bug as resolved due to no questions or comments.
- Mozilla representative — Mozilla asked if anyone had comments or outstanding issues and stated it would close on 3-May-2024 if none were raised.
- Community commenter — A participant asked whether the work was completed on schedule, referencing an action item to update PA Policy regarding disablement of OCSP and CRL services.
- Sectigo — Sectigo replied that the PA Policy update was completed on April 23, 2024, and acknowledged an oversight in not verifying that the reviewed post was saved to the bug.
- Community commenter — The participant thanked Sectigo for the transparent reply and said no worries.