← Sectigo cases
Bugzilla #1972547 Incident Policy Document Issue

Sectigo: Lack of technical controls for multiparty control access to Secure Zone

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo opened this CA Program bug after a WebTrust audit discovered that a CA Administrator could have sole physical access to a Secure Zone. Sectigo stated that the intent of its CP was to restrict this through policy, but that the CP language suggested the need for technical enforcement. The incident was identified during the audit process (auditor demonstration on 2025-02-24) and Sectigo confirmed on 2025-06-16 that no further mitigating controls or evidence were discovered. Sectigo reported that certificate issuance was not halted because it was not directly impacted, and it added clarifying language in the next version of the Sectigo WebPKI CP. As remediation, Sectigo updated its CP/CPS with clarifying language around physical access requirements and additional scope for Root CA Systems, and it committed to additional focus on avoiding ambiguous document language in future updates. The bug was marked RESOLVED with resolution FIXED, with a report closure summary requesting closure after action items were completed as described.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 14:01 UTC Confidence: 0.90 5 comments
Chronology
  1. Sectigo published WebPKI CP version 1.0 describing procedural enforcement for physical access to Certificate Systems.
  2. Sectigo started its annual WebTrust audit.
  3. During the datacenter visit, the auditor asked whether a Trusted Role employee could obtain physical access to datacenter racks by themselves, and this was demonstrated.
  4. Sectigo confirmed to its auditors that no further mitigating controls or evidence were discovered and declared the issue an incident.
  5. Sectigo opened this bug in the CA Program.
  6. Sectigo posted a report closure summary stating remediation was completed and requested closure.
Thread Activity
  1. Sectigo — Martijn Katerbarg posted a preliminary incident report describing the WebTrust audit finding about sole physical access to a Secure Zone and the need for technical enforcement implied by CP language.
  2. Sectigo — Martijn Katerbarg posted a full incident report with timeline details, stated certificate issuance was not halted, and described the incident as arising from CP language interpretation.
  3. Sectigo — Martijn Katerbarg indicated that a report closure summary would be posted if no questions were raised.
  4. Sectigo — Martijn Katerbarg posted the report closure summary, stating remediation via CP/CPS updates with clarifying physical access language and requesting closure after action items were completed.
  5. CCADB representative — i**********g@ccadb.org made a final call for comments and stated the incident report would be closed around 2025-07-15.
Participants
Sectigo CCADB representative
External References
Similar Local Cases
#1972158 RESOLVED Incident Audit Finding Opened 2025-06-14 · Closed 2025-07-16 · 99% similar
Sectigo: Lack of documentation for vulnerability NVD rating adjustment
#2000277 RESOLVED Incident Opened 2025-11-14 · Closed 2025-12-19 · 98% similar
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA
#1954580 RESOLVED Incident Revocation Issue Opened 2025-03-17 · Closed 2025-05-16 · 97% similar
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
#1985307 RESOLVED Incident Opened 2025-08-26 · Closed 2025-10-09 · 96% similar
Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs
#1991196 RESOLVED Incident Opened 2025-09-26 · Closed 2025-12-01 · 95% similar
Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA
#1869056 RESOLVED Incident Opened 2023-12-08 · Closed 2024-02-02 · 90% similar
Sectigo: Inadequate vulnerability scanning and patching
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 90% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1830088 RESOLVED Incident Opened 2023-04-26 · Closed 2024-03-27 · 89% similar
Sectigo: Late termination of privileged access to Certificate Systems

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action