← Sectigo cases
Bugzilla #1972547 Technical Compliance

Sectigo: Lack of technical controls for multiparty control access to Secure Zone

RESOLVED FIXED Sectigo
AI Summary

During a WebTrust audit, it was discovered that a CA Administrator could have sole physical access to a Secure Zone, which contradicted the intent of Sectigo's Certificate Policy (CP). The CP language indicated a need for technical enforcement of access controls, which was not in place. Although the incident did not halt certificate issuance, clarifying language was added to the CP to prevent future misinterpretations. The root cause was identified as the incorrect use of the term 'strictly enforced' in the policy documentation.

Model: gpt-4o-mini Generated: 2026-06-13 20:56 UTC Confidence: 0.90
Chronology
  1. Sectigo WebPKI CP version 1.0 published
  2. Non-compliance identified during audit
  3. Bug opened to report incident
  4. Report Closure Summary posted
Participants
Martijn Katerbarg
External References
Similar Local Cases
#1830088 RESOLVED Technical Compliance Opened 2023-04-26 · Closed 2024-03-27 · 58% similar
Sectigo: Late termination of privileged access to Certificate Systems
#1735761 RESOLVED Technical Compliance Opened 2021-10-14 · Closed 2023-02-22 · 57% similar
Sectigo: CRL validity beyond CPS allowed value
#1699756 RESOLVED Technical Compliance Opened 2021-03-19 · Closed 2022-11-14 · 47% similar
Sectigo: Reseller ZeroSSL and Private Key Generation
#1848280 RESOLVED Technical Compliance Opened 2023-08-11 · Closed 2023-10-12 · 42% similar
Microsoft PKI Services: 3-Month Access Review Process Failure
#1848279 RESOLVED Technical Compliance Opened 2023-08-11 · Closed 2023-10-12 · 40% similar
Microsoft PKI Services: Trusted Role Control Failure
#1746945 RESOLVED Technical Compliance Opened 2021-12-20 · Closed 2023-02-22 · 40% similar
Amazon Trust Services: Missing CAA Check For Test Website Certificates
#1983270 RESOLVED Technical Compliance Opened 2025-08-15 · Closed 2026-01-13 · 38% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review
#1772644 RESOLVED Technical Compliance Opened 2022-06-04 · Closed 2023-02-22 · 38% similar
Apple: CRL issuance frequency deviates from CPS in some cases

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action