← Sectigo cases
Bugzilla #1994454
Certificate Problem Report
Sectigo: Failure to reply to Certificate Problem Reports within 24 hours
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo experienced a failure to respond to Certificate Problem Reports (CPRs) within the required 24-hour timeframe due to a problem with their email queue. This issue was identified on October 13, 2025, and affected 150 certificates across various types, including TLS, S/MIME, and Code Signing. The root cause was traced to a logic change in their CRM system that disrupted the handling of CPR emails. Sectigo has since restored the functionality and implemented additional monitoring and alerting to prevent future occurrences.
Chronology
- Non-compliance start date identified
- Non-compliance identified and investigation initiated
- Preliminary incident report submitted
- Final report closure summary submitted
Participants
Martijn Katerbarg
External References
Similar Local Cases
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
Sectigo: Incorrect OCSP responses
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
Sectigo: Temporary unavailability for subset of CRLs
Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA
Sectigo: SC45 DCV Reuse Error
Sectigo: S/MIME certificates with (null) string value in subject attributes