Sectigo: Late receipt and disclosure to CCADB of ETSI audit letters
Sectigo filed this incident report after discovering that its ETSI audit letters for QWAC subordinate CAs listed an audit period of less than 365 days. Sectigo stated that, due to this unexpected audit period truncation, more than 3 months/92 days had already elapsed since the audit period end date when the audit letter details were submitted to CCADB. Sectigo said it requested its auditor to explain to CCADB Root Store Members why the final audit statement was not provided within 90 days of the Audit Period End date, and that the late disclosure violated both Mozilla and Chrome Root Program Policies. Sectigo reported that the CCADB records for 8 subordinate CA certificates did not receive details of updated audit letters within the required time. In the closure summary, Sectigo described remediation steps including updated internal practices and policies (peer review of draft audit letters, using CCADB’s Test Preliminary Audit Statements option, requesting written confirmation of the targeted audit period during planning, and attending biweekly calls with ETSI auditors). Mozilla indicated it would close the bug on 28-Feb-2025 unless there were remaining issues or questions, and the bug is marked RESOLVED with resolution FIXED.
- Sectigo received an initial ETSI audit plan from its auditor for QWAC subordinate CA certificates.
- Sectigo discussed the ongoing ETSI audit progress during a WebPKI Incident Response call.
- Sectigo learned the auditor had shortened the audit period end date without notifying Sectigo.
- Sectigo updated CCADB records with audit letter details after the audit period end date had already passed by more than 3 months.
- Sectigo posted an incident report closure summary and requested closure of the bug.
- Sectigo — Sectigo reported discovering that its ETSI audit letters had an audit period truncated to less than 365 days and said it disclosed the audit letters to CCADB after the allowed timeframe.
- Sectigo — Sectigo posted a detailed incident report describing the impact on CCADB records for 8 subordinate CA certificates and providing a timeline.
- Sectigo — Sectigo stated it would continue monitoring the bug and planned to post an incident report closure summary unless questions were raised.
- Sectigo — Sectigo provided an incident report closure summary, including root causes and remediation steps, and requested closure.
- Mozilla representative — Mozilla stated it would close the bug on Friday, 28-Feb-2025, unless there were remaining issues or questions.