← Sectigo cases
Bugzilla #1891039 Incident

Sectigo: Premature disabling of CRL generation for an inactive CA

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a compliance incident after disabling CRL generation for several expired CAs in March 2024. The incident was triggered when Sectigo noticed that one disabled CRL belonged to an expired S/MIME Root CA that also had two unexpired cross-certificates issued by a currently trusted root, meaning the CRL disablement affected certificates that were still unexpired. Sectigo stated it would resolve the matter by revoking the two cross-certified subordinate CA certificates. Sectigo’s incident report describes how a pre-release CRL Monitor began logging failures in March 2024, but alerting was not enabled, and the issue was later manually reviewed and escalated in April. Sectigo received Policy Authority authorization and marked the two affected CA certificates as revoked in its database, preparing for an offline revocation ceremony scheduled for April 17, 2024. In later comments, Sectigo requested the bug be marked resolved, and Mozilla asked whether any questions remained before closure; a reviewer also asked whether an action item was completed, and Sectigo responded that the PA Policy update had been completed on April 23, 2024 and acknowledged an oversight in posting the reviewed update to the bug.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 18:59 UTC Confidence: 0.90 7 comments
Chronology
  1. Sectigo disabled CRL generation for several expired CAs.
  2. Sectigo noticed that a disabled CRL belonged to an expired S/MIME root with unexpired cross-certificates, identifying a compliance incident.
  3. Sectigo received Policy Authority authorization to revoke the two affected CA certificates.
  4. Sectigo marked the two affected CA certificates as revoked in its database and prepared for the offline revocation ceremony.
  5. Sectigo completed the offline revocation ceremony for the affected CA certificates.
  6. Sectigo requested the bug be marked resolved and Mozilla indicated it would close if no issues remained.
Thread Activity
  1. Sectigo — Sectigo reported that disabling CRL generation for expired CAs caused a compliance incident because an expired S/MIME Root CA’s CRL was disabled while two unexpired cross-certificates existed, and said it would revoke those cross-certificates.
  2. Sectigo — Sectigo posted a fuller incident report with impact, timeline, and details of how the CRL Monitor failures were detected and escalated.
  3. Sectigo — Sectigo requested marking the bug as resolved due to no questions or comments.
  4. Mozilla representative — Mozilla asked if anyone had comments or outstanding issues and stated it would close on 3-May-2024 if none were raised.
  5. Community commenter — A participant asked whether the work was completed on schedule, referencing an action item to update PA Policy regarding disablement of OCSP and CRL services.
  6. Sectigo — Sectigo replied that the PA Policy update was completed on April 23, 2024, and acknowledged an oversight in not verifying that the reviewed post was saved to the bug.
  7. Community commenter — The participant thanked Sectigo for the transparent reply and said no worries.
Participants
Sectigo Mozilla representative Community commenter
Similar Local Cases
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 98% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 97% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 96% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1741777 RESOLVED Incident Opened 2021-11-18 · Closed 2023-02-22 · 95% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1869056 RESOLVED Incident Opened 2023-12-08 · Closed 2024-02-02 · 95% similar
Sectigo: Inadequate vulnerability scanning and patching
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 94% similar
Sectigo: Incorrect OCSP responses
#1830088 RESOLVED Incident Opened 2023-04-26 · Closed 2024-03-27 · 93% similar
Sectigo: Late termination of privileged access to Certificate Systems
#1991196 RESOLVED Incident Opened 2025-09-26 · Closed 2025-12-01 · 89% similar
Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action