Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs
Sectigo reported a self-discovered incident involving three recently established subordinate CAs whose CRLs were unavailable (HTTP 404) and whose OCSP responses returned an “unauthorized” response. Sectigo determined that the CRLs and OCSP responses were signed and available at its origin server, but were not being served by the CDN proxy. In response, Sectigo halted issuance from the affected subordinate CAs shortly after the incident was identified. The incident was resolved by 13:34 UTC when correct OCSP responses were being returned and CRL endpoints started working correctly. Sectigo later provided a root cause explanation that it incorrectly assumed the CDN proxy would forward all CRL/OCSP traffic, noting the proxy was configured to only allow specific CRL URLs and OCSP responses for specific subordinate CAs. Sectigo updated internal approval policies and customer guidance to ensure required details are verified before subordinate CA issuance, and requested closure after completing disclosed action items. The bug is marked RESOLVED with resolution FIXED.
- Sectigo identified that CRLs and OCSP responses for three newly established subordinate CAs were not being served correctly via the CDN proxy.
- Sectigo halted issuance from the affected subordinate CAs and later restored correct CRL/OCSP behavior.
- Sectigo completed the disclosed remediation action items and requested closure of the incident report.
- Sectigo — Opened a Preliminary Incident Report describing the CRL 404 and OCSP “unauthorized” responses, the decision to halt issuance, and the self-reported source of disclosure.
- Sectigo — Noted that the comment contained the full incident report rather than the preliminary report.
- Sectigo — Requested a Next-Update for 2025-09-30 based on action items.
- Sectigo — Provided the full closure summary with root cause, remediation steps (updated internal approval policies and customer guidance), and requested closure after completing action items.
- CCADB representative — Issued a final call for comments and stated the incident report would be closed around 2025-10-07 if no further questions were raised.