Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
Sectigo disclosed a compliance incident involving sixteen CCADB records for Cross-Certified Subordinate CA Certificates it issued to SSL.com. Sectigo said it has an ongoing duty to keep those CCADB records up to date, but SSL.com did not notify Sectigo promptly after publishing SSL.com CP/CPS v1.21 and v1.22. Sectigo determined that, by the time it became aware, the updated CP/CPS information was already disclosed too late to CCADB within the tightest disclosure deadline required by the root store policies, and that this qualified as a compliance incident. Sectigo reported that the affected CCADB records contained outdated CP/CPS information for longer than permitted by the Chrome Root Program Policy, and that SSL.com did not cease issuance during the incident. Sectigo stated it created the bug on 2025-01-20 and deployed scripts to automatically monitor and alert on changes to the CP/CPS repository, audit seal website, and CCADB records. In the closure summary, Sectigo reported remediation including a standing monthly call with SSL.com and two methods of automated monitoring, and requested closure; Mozilla indicated it intended to close the bug on 14-February-2025. The bug is marked RESOLVED with resolution FIXED.
- Sectigo issued sixteen Cross-Certified Subordinate CA Certificates to SSL.com.
- SSL.com published CP/CPS v1.21 (Sectigo was not notified promptly).
- SSL.com published CP/CPS v1.22 (Sectigo was not notified promptly).
- Sectigo identified that CP/CPS disclosures to CCADB were late and qualified as a compliance incident.
- Sectigo completed and deployed scripts to automatically monitor and alert on CP/CPS and related CCADB changes.
- Sectigo posted an incident report closure summary and requested closure of the bug.
- Sectigo — Opened an initial incident report stating that sixteen CCADB records contained outdated CP/CPS information because SSL.com did not notify Sectigo promptly, and said an incident report would follow by 2025-01-31.
- Sectigo — Posted an incident report describing the impact (outdated CP/CPS in sixteen CCADB records beyond permitted timelines) and provided a detailed timeline.
- Sectigo — Noted Sectigo would post an incident report closure summary by the following week unless questions were raised.
- SSL.com — SSL.com said it failed to notify Sectigo directly on two occasions, updated its CP/CPS Change Management procedure, and scheduled regular coordination meetings as corrective action.
- Sectigo — Provided an incident report closure summary with remediation steps (standing monthly call and automated monitoring) and requested closure of the bug.
- Mozilla representative — Stated an intention to close the bug on Friday, 14-February-2025.