← Sectigo cases
Bugzilla #1902310 Incident

Sectigo: Trusted Role Access provided prior to completion of onboarding process

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a compliance incident discovered during its annual WebTrust audit. The auditors found that access to Certificate Systems was granted to two employees before completion of criminal background checks, and to three additional employees before completion of formal validation training evidence. Sectigo stated that its CPS requires background checks before access is granted, and that while identity verification was completed, criminal background checks were completed after access was provided. For validation training, Sectigo said buddy-system training was completed for the employees but it only had “eye-witness accounts” as evidence, and the formal Validation Training Exam Course was completed after access was granted. Sectigo reported the issue to the Mozilla community to allow tracking of the errors and noted that its audit firm intended to call out these errors as findings in the upcoming WebTrust report. The incident handling action item was completed, and Mozilla indicated it would close the bug unless questions or issues remained. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 19:00 UTC Confidence: 0.88 5 comments
Chronology
  1. Certificate System accounts were created for Employee #1 and Employee #2 before criminal background checks were completed.
  2. A Certificate System account was created for Employee #3 in a validation capacity before formal validation training evidence was completed.
  3. Certificate System accounts were created for Employee #4 and Employee #5 in a validation capacity before formal validation training evidence was completed.
  4. Sectigo submitted the incident report describing the onboarding/access timing issues found during its annual WebTrust audit.
  5. Sectigo completed the final action item for incident handling.
Thread Activity
  1. Sectigo — Sectigo provided a preliminary incident report stating auditors found access granted before completion of background checks and validation training.
  2. Sectigo — Sectigo posted the full incident report, including CPS/EVG language discussion, impact, and a timeline of when access and checks/training occurred.
  3. Sectigo — Sectigo stated the final action item in the incident report was completed and asked to continue monitoring for questions.
  4. Sectigo — Tim Callan asked whether the bug could be closed.
  5. Mozilla representative — Mozilla stated it would close the bug on 10-Jul-2024 unless issues or questions remained.
Participants
Sectigo Mozilla representative
External References
Similar Local Cases
#1741777 RESOLVED Incident Opened 2021-11-18 · Closed 2023-02-22 · 100% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 98% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 98% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1869056 RESOLVED Incident Opened 2023-12-08 · Closed 2024-02-02 · 97% similar
Sectigo: Inadequate vulnerability scanning and patching
#1891039 RESOLVED Incident Opened 2024-04-11 · Closed 2024-05-05 · 96% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1830088 RESOLVED Incident Opened 2023-04-26 · Closed 2024-03-27 · 95% similar
Sectigo: Late termination of privileged access to Certificate Systems
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 93% similar
Sectigo: Incorrect OCSP responses
#1972158 RESOLVED Incident Audit Finding Opened 2025-06-14 · Closed 2025-07-16 · 90% similar
Sectigo: Lack of documentation for vulnerability NVD rating adjustment

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action