← Sectigo cases
Bugzilla #1945197 Self Reported Incident Audit Delay

Sectigo: Late receipt and disclosure to CCADB of ETSI audit letters

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo filed this incident report after discovering that its ETSI audit letters for QWAC subordinate CAs listed an audit period of less than 365 days. Sectigo stated that, due to this unexpected audit period truncation, more than 3 months/92 days had already elapsed since the audit period end date when the audit letter details were submitted to CCADB. Sectigo said it requested its auditor to explain to CCADB Root Store Members why the final audit statement was not provided within 90 days of the Audit Period End date, and that the late disclosure violated both Mozilla and Chrome Root Program Policies. Sectigo reported that the CCADB records for 8 subordinate CA certificates did not receive details of updated audit letters within the required time. In the closure summary, Sectigo described remediation steps including updated internal practices and policies (peer review of draft audit letters, using CCADB’s Test Preliminary Audit Statements option, requesting written confirmation of the targeted audit period during planning, and attending biweekly calls with ETSI auditors). Mozilla indicated it would close the bug on 28-Feb-2025 unless there were remaining issues or questions, and the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 19:03 UTC Confidence: 0.90 5 comments
Chronology
  1. Sectigo received an initial ETSI audit plan from its auditor for QWAC subordinate CA certificates.
  2. Sectigo discussed the ongoing ETSI audit progress during a WebPKI Incident Response call.
  3. Sectigo learned the auditor had shortened the audit period end date without notifying Sectigo.
  4. Sectigo updated CCADB records with audit letter details after the audit period end date had already passed by more than 3 months.
  5. Sectigo posted an incident report closure summary and requested closure of the bug.
Thread Activity
  1. Sectigo — Sectigo reported discovering that its ETSI audit letters had an audit period truncated to less than 365 days and said it disclosed the audit letters to CCADB after the allowed timeframe.
  2. Sectigo — Sectigo posted a detailed incident report describing the impact on CCADB records for 8 subordinate CA certificates and providing a timeline.
  3. Sectigo — Sectigo stated it would continue monitoring the bug and planned to post an incident report closure summary unless questions were raised.
  4. Sectigo — Sectigo provided an incident report closure summary, including root causes and remediation steps, and requested closure.
  5. Mozilla representative — Mozilla stated it would close the bug on Friday, 28-Feb-2025, unless there were remaining issues or questions.
Participants
Sectigo Mozilla representative
External References
Similar Local Cases
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 100% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 95% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 95% similar
Sectigo: Incorrect JOI for federal credit unions
#1796803 RESOLVED Self Reported Incident Opened 2022-10-21 · Closed 2023-02-22 · 93% similar
Sectigo: Issuance of ECC leaf certificates with non-DER encoded keyUsage
#1718785 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2024-06-30 · 89% similar
Sectigo: 2020 failure to respond to CPRs discovered
#1793787 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Repository Issue Opened 2022-10-05 · Closed 2023-02-22 · 87% similar
Sectigo: Non-existent hostname in CDP and AIA URLs
#1619359 RESOLVED Self Reported Incident Opened 2020-03-02 · Closed 2023-02-22 · 87% similar
Sectigo: Failure to provide a preliminary report within 24 hours
#1620561 RESOLVED Self Reported Incident Opened 2020-03-06 · Closed 2023-02-22 · 87% similar
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action