← Sectigo cases
Bugzilla #2000277 Certificate Problem Report

Sectigo: Certificate issuance by non-compliant Extant S/MIME CA

RESOLVED FIXED Sectigo
AI Summary

Sectigo reported an incident involving the issuance of S/MIME certificates by six non-compliant Extant S/MIME CAs. This issue arose due to a software bug that allowed these CAs to continue issuing certificates despite being marked as disabled. A total of 996 certificates were issued after September 15, 2024, with 531 remaining valid at the time the incident was identified. Sectigo has since implemented a bug fix and refactored their SubCA management to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 20:55 UTC Confidence: 1.00
Chronology
  1. Non-compliance start date
  2. Non-compliance identified
  3. Non-compliance end date
  4. Incident report closure summary provided
Participants
Martijn Katerbarg
Similar Local Cases
#1897538 RESOLVED Certificate Problem Report Opened 2024-05-17 · Closed 2024-06-14 · 61% similar
Sectigo: Incorrectly included registrationStateOrProvince in PSD-based cabfOrganizationIdentifier extension
#1985307 RESOLVED Certificate Problem Report Opened 2025-08-26 · Closed 2025-10-09 · 61% similar
Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs
#1853987 RESOLVED Certificate Problem Report Opened 2023-09-19 · Closed 2023-10-12 · 60% similar
Sectigo: S/MIME certificates with (null) string value in subject attributes
#1902748 RESOLVED Certificate Problem Report Opened 2024-06-14 · Closed 2024-08-28 · 60% similar
Sectigo: QWAC certificates issued with incorrect subject:organizationIdentifier attribute value
#1977253 RESOLVED Certificate Problem Report Opened 2025-07-14 · Closed 2025-09-15 · 60% similar
Sectigo: OV reuse data applied for wrong organization
#1991196 RESOLVED Certificate Problem Report Opened 2025-09-26 · Closed 2025-12-01 · 60% similar
Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA
#2010885 RESOLVED Certificate Problem Report Opened 2026-01-16 · Closed 2026-03-05 · 60% similar
Sectigo: Inaccuracy of CCADB-Disclosed URL for eIDAS CP/CPS
#1763203 RESOLVED Certificate Problem Report Opened 2022-04-05 · Closed 2023-02-22 · 59% similar
Sectigo: Incorrect OCSP responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action