← DigiCert cases
Bugzilla #1945536 Ca Documents Audit Delay

DigiCert incident report on outdated CP/CPS data in CCADB for 13 roots

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert opened this incident report after a Sectigo employee notified it that CCADB was showing outdated CP/CPS information for 13 DigiCert roots. DigiCert said the problem involved an outdated CP/CPS entry appearing in CCADB and later explained that the issue was tied to an ALV error, a missed case notification, and failure to mark older documents as superseded. DigiCert updated its SOPs to require two people to review a case, added checks to its automated CCADB monitoring, and said it submitted an enhancement request for notifications to go to all CCADB contacts. The discussion also covered whether CP/CPS v7.04 had been disclosed in time and whether the older documents should have been superseded; DigiCert ultimately revised its root-cause summary and asked for closure. The bug was resolved as FIXED and the thread ended with closure requests after the incident report summary was posted.

Model: gpt-5.4-mini Generated: 2026-06-13 11:46 UTC Revised: 2026-06-16 19:19 UTC Confidence: 0.93 44 comments
Chronology
  1. DigiCert published Public Trust CP/CPS v7.04.
  2. DigiCert created CCADB case 00002121 to update audits and CP/CPS.
  3. Sectigo reported that CCADB showed outdated CP/CPS information for 13 DigiCert roots.
  4. CCADB case 00002192 was approved for CP/CPS v7.04.
  5. DigiCert updated its SOP to mark outdated documents as superseded and require dual review.
Thread Activity
  1. DigiCert — DigiCert opened the bug with a preliminary incident report saying 13 root records showed an outdated CP/CPS entry in CCADB.
  2. Google representative — Mozilla asked DigiCert to clarify the impacted roots, the CCADB links involved, and the ALV-related timeline.
  3. DigiCert — DigiCert said an employee did not run ALV or act on the case notification, and that the SOP needed updates for superseding documents.
  4. Mozilla representative — Mozilla said the delayed disclosure was not promptly updated in CCADB and asked DigiCert to revise its root-cause analysis.
  5. DigiCert — DigiCert posted a closure summary with incident description, root causes, remediation, and a request to close the bug.
  6. Sectigo — Sectigo attached the CPR that led to the incident bug and reiterated concerns about the delayed disclosure.
  7. DigiCert — DigiCert said it had no additional comments and asked for the bug to be closed.
Participants
DigiCert Google representative Mozilla representative Sectigo CCADB representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1925106 RESOLVED Ca Documents Opened 2024-10-16 · Closed 2025-07-22 · 100% similar
DigiCert: Incorrect CP listed in CCADB
#2013375 RESOLVED Ca Documents Common Ca Database Opened 2026-01-29 · Closed 2026-02-18 · 85% similar
DigiCert: Issues with CCADB entries
#1904041 RESOLVED Ca Documents Self Reported Incident Opened 2024-06-21 · Closed 2025-07-01 · 84% similar
NETLOCK: Intermediate CA Certificate not disclosed to CCADB
#1417771 RESOLVED Ca Documents Incident Opened 2017-11-16 · Closed 2024-06-30 · 77% similar
DigiCert: Symantec non-constrained/non-disclosed intermediate CA certificates
#1894111 RESOLVED Ca Documents Self Reported Incident Opened 2024-04-29 · Closed 2025-01-22 · 70% similar
Entrust: Not updating CPR Problem Reporting Mechanism fields in CCADB
#1814197 RESOLVED Ca Documents Opened 2023-01-31 · Closed 2023-02-14 · 69% similar
DigiCert: Late CP/CPS CCADB uploads
#1950144 RESOLVED Incident Self Reported Incident Opened 2025-02-24 · Closed 2026-06-11 · 69% similar
DigiCert: Threat of legal action to stifle Bugzilla discourse
#2004300 RESOLVED Audit Delay Opened 2025-12-05 · Closed 2025-12-24 · 69% similar
Telia: Delayed submission of preliminary audit incident report

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action