Sectigo: Lack of technical controls for multiparty control access to Secure Zone
Sectigo opened this CA Program bug after a WebTrust audit discovered that a CA Administrator could have sole physical access to a Secure Zone. Sectigo stated that the intent of its CP was to restrict this through policy, but that the CP language suggested the need for technical enforcement. The incident was identified during the audit process (auditor demonstration on 2025-02-24) and Sectigo confirmed on 2025-06-16 that no further mitigating controls or evidence were discovered. Sectigo reported that certificate issuance was not halted because it was not directly impacted, and it added clarifying language in the next version of the Sectigo WebPKI CP. As remediation, Sectigo updated its CP/CPS with clarifying language around physical access requirements and additional scope for Root CA Systems, and it committed to additional focus on avoiding ambiguous document language in future updates. The bug was marked RESOLVED with resolution FIXED, with a report closure summary requesting closure after action items were completed as described.
- Sectigo published WebPKI CP version 1.0 describing procedural enforcement for physical access to Certificate Systems.
- Sectigo started its annual WebTrust audit.
- During the datacenter visit, the auditor asked whether a Trusted Role employee could obtain physical access to datacenter racks by themselves, and this was demonstrated.
- Sectigo confirmed to its auditors that no further mitigating controls or evidence were discovered and declared the issue an incident.
- Sectigo opened this bug in the CA Program.
- Sectigo posted a report closure summary stating remediation was completed and requested closure.
- Sectigo — Martijn Katerbarg posted a preliminary incident report describing the WebTrust audit finding about sole physical access to a Secure Zone and the need for technical enforcement implied by CP language.
- Sectigo — Martijn Katerbarg posted a full incident report with timeline details, stated certificate issuance was not halted, and described the incident as arising from CP language interpretation.
- Sectigo — Martijn Katerbarg indicated that a report closure summary would be posted if no questions were raised.
- Sectigo — Martijn Katerbarg posted the report closure summary, stating remediation via CP/CPS updates with clarifying physical access language and requesting closure after action items were completed.
- CCADB representative — i**********g@ccadb.org made a final call for comments and stated the incident report would be closed around 2025-07-15.