← Sectigo cases
Bugzilla #1991196 Incident

Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported an incident in which the OCSP, caIssuers, and CRL endpoints for a single Subordinate CA became unavailable. The issue was triggered when Sectigo noticed two leaf certificates attributed to Sectigo on OCSPWatch showing DNS errors on 2025-09-25, and its investigation found that the domain used for the endpoints had not remained under Sectigo’s control and had recently expired. Sectigo stated that the relevant non-compliance related to CRLs being required to be available via a publicly-accessible HTTP URL. While working on reinstating the domain, Sectigo decided to revoke the affected leaf certificates and the corresponding Subordinate CA certificate. Sectigo reported that 17 leaf certificates were impacted and that it revoked the remaining 13 certificates, resulting in 0 remaining valid certificates. Sectigo also stated that issuance for the affected Subordinate CA was halted to prevent increased impact, and it requested closure after completing its disclosed action items.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 19:04 UTC Confidence: 0.90 6 comments
Chronology
  1. Sectigo identified DNS errors for OCSP/caIssuers/CRL endpoints for two leaf certificates attributed to Sectigo.
  2. Sectigo completed the incident period remediation actions, including revocation decisions for affected certificates.
  3. Sectigo reported review completion and requested closure of the incident report.
Thread Activity
  1. Sectigo — Martijn Katerbarg opened a preliminary incident report stating the endpoint domain had expired and that Sectigo planned to reinstate the domain and revoke affected leaf certificates and the corresponding Subordinate CA.
  2. Sectigo — Martijn Katerbarg added an attachment listing affected certificates.
  3. Sectigo — Martijn Katerbarg posted the full incident report, stating Sectigo decided to revoke the affected leaf certificates and the corresponding Subordinate CA and reporting the impact (17 total certificates, 13 remaining valid revoked).
  4. Sectigo — Martijn Katerbarg requested a next update for 2025-10-30.
  5. Sectigo — Martijn Katerbarg reported completion of action items, described the root cause (domain transfer gap during the 2017 carve-out), stated remediation (revocation of leaf certificates and the Subordinate CA), and requested closure.
  6. CCADB representative — CCADB’s incident-reporting account issued a final call for comments and noted the report would be closed approximately 2025-11-06.
Participants
Sectigo CCADB representative
Similar Local Cases
#1985307 RESOLVED Incident Opened 2025-08-26 · Closed 2025-10-09 · 99% similar
Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs
#2000277 RESOLVED Incident Opened 2025-11-14 · Closed 2025-12-19 · 99% similar
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA
#1954580 RESOLVED Incident Revocation Issue Opened 2025-03-17 · Closed 2025-05-16 · 96% similar
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
#1972158 RESOLVED Incident Audit Finding Opened 2025-06-14 · Closed 2025-07-16 · 96% similar
Sectigo: Lack of documentation for vulnerability NVD rating adjustment
#1972547 RESOLVED Incident Policy Document Issue Opened 2025-06-17 · Closed 2025-07-16 · 95% similar
Sectigo: Lack of technical controls for multiparty control access to Secure Zone
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 89% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1891039 RESOLVED Incident Opened 2024-04-11 · Closed 2024-05-05 · 89% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 88% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action