Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA
Sectigo reported an incident in which the OCSP, caIssuers, and CRL endpoints for a single Subordinate CA became unavailable. The issue was triggered when Sectigo noticed two leaf certificates attributed to Sectigo on OCSPWatch showing DNS errors on 2025-09-25, and its investigation found that the domain used for the endpoints had not remained under Sectigo’s control and had recently expired. Sectigo stated that the relevant non-compliance related to CRLs being required to be available via a publicly-accessible HTTP URL. While working on reinstating the domain, Sectigo decided to revoke the affected leaf certificates and the corresponding Subordinate CA certificate. Sectigo reported that 17 leaf certificates were impacted and that it revoked the remaining 13 certificates, resulting in 0 remaining valid certificates. Sectigo also stated that issuance for the affected Subordinate CA was halted to prevent increased impact, and it requested closure after completing its disclosed action items.
- Sectigo identified DNS errors for OCSP/caIssuers/CRL endpoints for two leaf certificates attributed to Sectigo.
- Sectigo completed the incident period remediation actions, including revocation decisions for affected certificates.
- Sectigo reported review completion and requested closure of the incident report.
- Sectigo — Martijn Katerbarg opened a preliminary incident report stating the endpoint domain had expired and that Sectigo planned to reinstate the domain and revoke affected leaf certificates and the corresponding Subordinate CA.
- Sectigo — Martijn Katerbarg added an attachment listing affected certificates.
- Sectigo — Martijn Katerbarg posted the full incident report, stating Sectigo decided to revoke the affected leaf certificates and the corresponding Subordinate CA and reporting the impact (17 total certificates, 13 remaining valid revoked).
- Sectigo — Martijn Katerbarg requested a next update for 2025-10-30.
- Sectigo — Martijn Katerbarg reported completion of action items, described the root cause (domain transfer gap during the 2017 carve-out), stated remediation (revocation of leaf certificates and the Subordinate CA), and requested closure.
- CCADB representative — CCADB’s incident-reporting account issued a final call for comments and noted the report would be closed approximately 2025-11-06.