← SSL.com cases
Bugzilla #1942651 Self Reported Incident Policy Document Issue

Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo disclosed a compliance incident involving sixteen CCADB records for Cross-Certified Subordinate CA Certificates it issued to SSL.com. Sectigo said it has an ongoing duty to keep those CCADB records up to date, but SSL.com did not notify Sectigo promptly after publishing SSL.com CP/CPS v1.21 and v1.22. Sectigo determined that, by the time it became aware, the updated CP/CPS information was already disclosed too late to CCADB within the tightest disclosure deadline required by the root store policies, and that this qualified as a compliance incident. Sectigo reported that the affected CCADB records contained outdated CP/CPS information for longer than permitted by the Chrome Root Program Policy, and that SSL.com did not cease issuance during the incident. Sectigo stated it created the bug on 2025-01-20 and deployed scripts to automatically monitor and alert on changes to the CP/CPS repository, audit seal website, and CCADB records. In the closure summary, Sectigo reported remediation including a standing monthly call with SSL.com and two methods of automated monitoring, and requested closure; Mozilla indicated it intended to close the bug on 14-February-2025. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:51 UTC Confidence: 0.86 6 comments
Chronology
  1. Sectigo issued sixteen Cross-Certified Subordinate CA Certificates to SSL.com.
  2. SSL.com published CP/CPS v1.21 (Sectigo was not notified promptly).
  3. SSL.com published CP/CPS v1.22 (Sectigo was not notified promptly).
  4. Sectigo identified that CP/CPS disclosures to CCADB were late and qualified as a compliance incident.
  5. Sectigo completed and deployed scripts to automatically monitor and alert on CP/CPS and related CCADB changes.
  6. Sectigo posted an incident report closure summary and requested closure of the bug.
Thread Activity
  1. Sectigo — Opened an initial incident report stating that sixteen CCADB records contained outdated CP/CPS information because SSL.com did not notify Sectigo promptly, and said an incident report would follow by 2025-01-31.
  2. Sectigo — Posted an incident report describing the impact (outdated CP/CPS in sixteen CCADB records beyond permitted timelines) and provided a detailed timeline.
  3. Sectigo — Noted Sectigo would post an incident report closure summary by the following week unless questions were raised.
  4. SSL.com — SSL.com said it failed to notify Sectigo directly on two occasions, updated its CP/CPS Change Management procedure, and scheduled regular coordination meetings as corrective action.
  5. Sectigo — Provided an incident report closure summary with remediation steps (standing monthly call and automated monitoring) and requested closure of the bug.
  6. Mozilla representative — Stated an intention to close the bug on Friday, 14-February-2025.
Participants
Sectigo SSL.com Mozilla representative
External References
Similar Local Cases
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 100% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1790693 RESOLVED Self Reported Incident Revocation Issue Opened 2022-09-13 · Closed 2023-03-24 · 89% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1962809 RESOLVED Self Reported Incident Revocation Issue Opened 2025-04-25 · Closed 2025-07-28 · 87% similar
SSL.com: Expired certificate for a “Valid” Test Website
#1796803 RESOLVED Self Reported Incident Opened 2022-10-21 · Closed 2023-02-22 · 82% similar
Sectigo: Issuance of ECC leaf certificates with non-DER encoded keyUsage
#1945197 RESOLVED Self Reported Incident Audit Delay Opened 2025-01-31 · Closed 2025-02-28 · 81% similar
Sectigo: Late receipt and disclosure to CCADB of ETSI audit letters
#1784881 RESOLVED Policy Document Issue Self Reported Incident Opened 2022-08-15 · Closed 2023-02-22 · 79% similar
SwissSign: Missed deadline of publication of 6 CPs and 1 CP/CPS
#1947034 RESOLVED Policy Document Issue Self Reported Incident Opened 2025-02-09 · Closed 2025-04-11 · 79% similar
Chunghwa Telecom: outdated and stale policy documents disclosed to the CCADB
#2029230 RESOLVED Self Reported Incident Revocation Issue Opened 2026-04-03 · Closed 2026-05-28 · 78% similar
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action