← DigiCert cases
Bugzilla #1950144 Incident Self Reported Incident

DigiCert legal threat to Sectigo comments and resulting transparency dispute

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns DigiCert’s sending of a cease-and-desist letter to Sectigo over comments made in Bugzilla about DigiCert’s handling of a TRO connected to Bugzilla 1910805. The bug was opened by Sectigo’s Brian Holland, who said the letter was an attempt to stifle open discussion and that DigiCert had threatened legal action if the comments continued. DigiCert initially said it sent the letter to address what it viewed as misleading statements, then later acknowledged that sending the letter was a mistake and not in the best interest of transparency. DigiCert also stated that it would use Mozilla’s Community Participation Guidelines rather than external legal process for future forum-abuse concerns, and it described an internal ombudsperson process for raising concerns. The thread later included a full incident report and closure summary from DigiCert, which said the event did not involve certificates, but did involve legal action that could have had a dampening effect on public discussion. The current thread state shows DigiCert saying it has no additional comments and asking whether the matter can be considered resolved, while other participants continued to ask for more explanation and safeguards.

Model: gpt-5.4-mini Generated: 2026-06-13 11:47 UTC Revised: 2026-06-16 17:28 UTC Confidence: 0.97 75 comments
Chronology
  1. DigiCert learned a TRO had been filed in connection with the revocation matter later discussed in Bugzilla 1910805.
  2. DigiCert’s law firm sent a cease-and-desist letter to Sectigo about Bugzilla comments concerning the TRO and DigiCert’s operations.
  3. Sectigo responded to the letter and DigiCert later said the matter was considered resolved by its legal team.
  4. Sectigo opened Bugzilla 1950144 to disclose and challenge the legal letter.
  5. DigiCert posted a full incident report and said the letter could have dampened public discussion.
  6. DigiCert said it had finalized an ombudsperson program with a four-person team.
  7. DigiCert posted a closure summary and action items for handling similar legal issues in the future.
Thread Activity
  1. Sectigo — Brian Holland opened the bug and said DigiCert’s lawyers sent a letter demanding that Sectigo stop statements about DigiCert in Bugzilla.
  2. DigiCert — DigiCert said it sent the letter to defend the integrity of the forum and to address what it viewed as misleading statements.
  3. Mozilla representative — Mozilla said open discussion is important and that actions chilling participation are deeply damaging to the community.
  4. DigiCert — DigiCert said it had voluntarily disclosed the TRO, that the letter was sent because of competitor comments, and asked to close the issue because it saw no compliance violation.
  5. DigiCert — DigiCert acknowledged the letter was not in the best interest of transparency and said it regretted sending it.
  6. Google representative — Chrome Root Program said the discussion should continue in the bug and that intimidating participation is unacceptable.
  7. DigiCert — DigiCert posted a full incident report explaining the letter, its impact, and its planned remediation.
  8. DigiCert — DigiCert said it was setting up an independent ombudsperson contact process.
  9. DigiCert — DigiCert said the ombudsperson program was finalized and provided the contact address t**********y@digicert.com.
  10. DigiCert — DigiCert posted a closure summary describing the incident, root causes, and action items.
  11. Community commenter — Jeremy Rowley said he resigned in July 2024, later returned in a different role, and was not part of incident response.
  12. DigiCert — DigiCert said the ombudsperson process would be documented in its CPS and that it was evaluating adding an external representative.
Participants
Sectigo DigiCert Mozilla representative Google representative Community commenter HARICA Disabled representative Hezmatt representative 0266662 representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1894560 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-05-01 · Closed 2024-07-03 · 100% similar
DigiCert: Incorrect case in Business Category
#1978163 RESOLVED Self Reported Incident Opened 2025-07-18 · Closed 2025-10-29 · 100% similar
DigiCert: Re-use of WHOIS validation shortly after deadline
#2009491 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-01-09 · Closed 2026-02-17 · 100% similar
DigiCert: Several non-functioning AIA URLs
#1962829 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2025-04-26 · Closed 2026-04-26 · 95% similar
Microsoft PKI Services: Policy document bug
#1647084 RESOLVED Self Reported Incident Incident Opened 2020-06-20 · Closed 2023-02-22 · 95% similar
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
#1649277 RESOLVED Self Reported Incident Incident Opened 2020-06-29 · Closed 2023-02-22 · 95% similar
DigiCert: Failure to provide a preliminary report within 24 hours.
#1649951 RESOLVED Self Reported Incident Revocation Issue Opened 2020-07-02 · Closed 2023-02-22 · 95% similar
DigiCert: Incorrect OCSP Delegated Responder Certificate
#2004699 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2025-12-08 Still Open · 94% similar
Netlock: CA in AIA in PEM format

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action