← Sectigo cases
Bugzilla #1985307 Incident

Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a self-discovered incident involving three recently established subordinate CAs whose CRLs were unavailable (HTTP 404) and whose OCSP responses returned an “unauthorized” response. Sectigo determined that the CRLs and OCSP responses were signed and available at its origin server, but were not being served by the CDN proxy. In response, Sectigo halted issuance from the affected subordinate CAs shortly after the incident was identified. The incident was resolved by 13:34 UTC when correct OCSP responses were being returned and CRL endpoints started working correctly. Sectigo later provided a root cause explanation that it incorrectly assumed the CDN proxy would forward all CRL/OCSP traffic, noting the proxy was configured to only allow specific CRL URLs and OCSP responses for specific subordinate CAs. Sectigo updated internal approval policies and customer guidance to ensure required details are verified before subordinate CA issuance, and requested closure after completing disclosed action items. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 19:04 UTC Confidence: 0.90 6 comments
Chronology
  1. Sectigo identified that CRLs and OCSP responses for three newly established subordinate CAs were not being served correctly via the CDN proxy.
  2. Sectigo halted issuance from the affected subordinate CAs and later restored correct CRL/OCSP behavior.
  3. Sectigo completed the disclosed remediation action items and requested closure of the incident report.
Thread Activity
  1. Sectigo — Opened a Preliminary Incident Report describing the CRL 404 and OCSP “unauthorized” responses, the decision to halt issuance, and the self-reported source of disclosure.
  2. Sectigo — Noted that the comment contained the full incident report rather than the preliminary report.
  3. Sectigo — Requested a Next-Update for 2025-09-30 based on action items.
  4. Sectigo — Provided the full closure summary with root cause, remediation steps (updated internal approval policies and customer guidance), and requested closure after completing action items.
  5. CCADB representative — Issued a final call for comments and stated the incident report would be closed around 2025-10-07 if no further questions were raised.
Participants
Sectigo CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1991196 RESOLVED Incident Opened 2025-09-26 · Closed 2025-12-01 · 99% similar
Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA
#1954580 RESOLVED Incident Revocation Issue Opened 2025-03-17 · Closed 2025-05-16 · 98% similar
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
#2000277 RESOLVED Incident Opened 2025-11-14 · Closed 2025-12-19 · 97% similar
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA
#1972158 RESOLVED Incident Audit Finding Opened 2025-06-14 · Closed 2025-07-16 · 96% similar
Sectigo: Lack of documentation for vulnerability NVD rating adjustment
#1972547 RESOLVED Incident Policy Document Issue Opened 2025-06-17 · Closed 2025-07-16 · 96% similar
Sectigo: Lack of technical controls for multiparty control access to Secure Zone
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 89% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1741777 RESOLVED Incident Opened 2021-11-18 · Closed 2023-02-22 · 87% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1869056 RESOLVED Incident Opened 2023-12-08 · Closed 2024-02-02 · 87% similar
Sectigo: Inadequate vulnerability scanning and patching

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action