← Sectigo cases
Bugzilla #1945197 Certificate Problem Report

Sectigo: Late receipt and disclosure to CCADB of ETSI audit letters

RESOLVED FIXED Sectigo
AI Summary

Sectigo reported a late disclosure of ETSI audit letters for their QWAC Subordinate CAs, which violated Mozilla and Chrome Root Program Policies. The audit period was unexpectedly shortened to less than 365 days without notification, leading to a delay in submission to CCADB. Sectigo has since updated their internal practices to prevent future occurrences, including improved communication with auditors and a more thorough review process for audit letters.

Model: gpt-4o-mini Generated: 2026-06-13 20:56 UTC Confidence: 0.90
Chronology
  1. Sectigo discovers shortened audit period while submitting ETSI audit letters.
  2. Sectigo submits incident report detailing the late disclosure.
  3. Incident report closure summary provided by Sectigo.
Participants
Martijn Katerbarg B. Wilson
External References
Similar Local Cases
#2019995 RESOLVED Certificate Problem Report Opened 2026-02-27 · Closed 2026-04-08 · 59% similar
Sectigo: Package patching gap within Certificate Systems
#1954580 RESOLVED Certificate Problem Report Opened 2025-03-17 · Closed 2025-05-16 · 58% similar
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
#1991196 RESOLVED Certificate Problem Report Opened 2025-09-26 · Closed 2025-12-01 · 58% similar
Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA
#2010885 RESOLVED Certificate Problem Report Opened 2026-01-16 · Closed 2026-03-05 · 58% similar
Sectigo: Inaccuracy of CCADB-Disclosed URL for eIDAS CP/CPS
#1902748 RESOLVED Certificate Problem Report Opened 2024-06-14 · Closed 2024-08-28 · 57% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
#1972158 RESOLVED Certificate Problem Report Opened 2025-06-14 · Closed 2025-07-16 · 57% similar
Sectigo: Lack of documentation for vulnerability NVD rating adjustment
#1977253 RESOLVED Certificate Problem Report Opened 2025-07-14 · Closed 2025-09-15 · 57% similar
Sectigo: OV reuse data applied for wrong organization
#1985307 RESOLVED Certificate Problem Report Opened 2025-08-26 · Closed 2025-10-09 · 57% similar
Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action