← Sectigo cases
Bugzilla #1985307 Certificate Problem Report

Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs

RESOLVED FIXED Sectigo
AI Summary

On August 26, 2025, Sectigo identified that CRLs issued by three newly established Subordinate CAs were returning a 404 response, and OCSP responses were unauthorized. This issue led to a halt in certificate issuance from these CAs. The problem was traced back to the CDN proxy not properly forwarding the necessary traffic, despite the endpoints being operational. The incident was resolved the same day, and Sectigo has since updated its internal policies to prevent recurrence.

Model: gpt-4o-mini Generated: 2026-06-13 20:56 UTC Confidence: 0.95
Chronology
  1. CRLs and OCSP responses for 3 Subordinate CAs were found unavailable.
  2. Issuance from the affected Subordinate CAs was halted.
  3. The incident was resolved by 13:34 UTC.
  4. All action items related to the incident were completed.
Participants
Martijn Katerbarg
Similar Local Cases
#2000277 RESOLVED Certificate Problem Report Opened 2025-11-14 · Closed 2025-12-19 · 61% similar
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA
#1853987 RESOLVED Certificate Problem Report Opened 2023-09-19 · Closed 2023-10-12 · 58% similar
Sectigo: S/MIME certificates with (null) string value in subject attributes
#1897538 RESOLVED Certificate Problem Report Opened 2024-05-17 · Closed 2024-06-14 · 58% similar
Sectigo: Incorrectly included registrationStateOrProvince in PSD-based cabfOrganizationIdentifier extension
#1912225 RESOLVED Certificate Problem Report Opened 2024-08-08 · Closed 2024-09-26 · 58% similar
Sectigo: HTML encoded characters in subject attribute values
#1946927 RESOLVED Certificate Problem Report Opened 2025-02-08 · Closed 2025-05-16 · 58% similar
Sectigo: Intermittent OCSP unauthorized responses for certificates older than 15 minutes
#1994454 RESOLVED Certificate Problem Report Opened 2025-10-15 · Closed 2025-12-11 · 58% similar
Sectigo: Failure to reply to Certificate Problem Reports within 24 hours
#2031087 RESOLVED Certificate Problem Report Opened 2026-04-11 · Closed 2026-06-06 · 58% similar
Sectigo: Partial OCSP response publication delay for newly issued certificates
#1902748 RESOLVED Certificate Problem Report Opened 2024-06-14 · Closed 2024-08-28 · 57% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action