← Sectigo cases
Bugzilla #2000277 Incident

Sectigo: Certificate issuance by non-compliant Extant S/MIME CA

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a self-discovered incident involving its non-compliant Extant S/MIME CAs. The company became aware that 6 of its Extant S/MIME CAs may have issued S/MIME certificates on and after September 15, 2024, and it investigated the scope and impact. Sectigo stated that 5 of the 6 non-compliant Extant S/MIME CAs were previously marked as disabled in its system, but a software bug allowed continued usage for new issuance; the remaining CA had not previously been identified as non-compliant and therefore was not disabled until recently. Sectigo reported that 996 certificates were issued since 2024-09-15, with 531 remaining valid (unexpired and unrevoked) when the incident was identified, and that issuance by the affected CAs was halted due to a software bugfix prior to identification. As remediation, Sectigo said it completed refactoring of its SubCA management to add technical constraints against S/MIME SubCA profile requirements and implemented a bugfix to prevent usage of unauthorized S/MIME SubCAs. Sectigo requested closure, stating that the disclosed action items were completed as described.

Model: gpt-5.4-nano Generated: 2026-06-13 20:55 UTC Revised: 2026-06-16 19:05 UTC Confidence: 0.90 6 comments
Chronology
  1. Non-compliance period began for the Extant S/MIME CA certificates, per Sectigo’s incident timeline.
  2. Sectigo identified the incident after discovering that non-compliant Extant S/MIME CAs had issued S/MIME certificates on or after 2024-09-15.
  3. Sectigo’s incident timeline indicates the non-compliance ended.
  4. Sectigo provided a report closure summary and requested closure after remediation was completed.
Thread Activity
  1. Sectigo — Opened a preliminary incident report stating Sectigo became aware that one or more non-compliant Extant S/MIME CAs may have issued S/MIME certificates on or after 2024-09-15 and that it was investigating scope and impact.
  2. Sectigo — Provided a full incident report with details including that 6 non-compliant Extant S/MIME CAs issued 996 certificates since 2024-09-15 and described the software bug and remediation timeline.
  3. Sectigo — Noted that Sectigo was monitoring the bug for questions or comments.
  4. Sectigo — Submitted a report closure summary stating remediation was completed (refactoring and a bugfix) and requested closure.
  5. CCADB representative — Issued a final call for comments and indicated the report would be closed approximately 2025-12-18 unless needinfo was provided.
Participants
Sectigo CCADB representative
Similar Local Cases
#1991196 RESOLVED Incident Opened 2025-09-26 · Closed 2025-12-01 · 99% similar
Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA
#1972158 RESOLVED Incident Audit Finding Opened 2025-06-14 · Closed 2025-07-16 · 98% similar
Sectigo: Lack of documentation for vulnerability NVD rating adjustment
#1972547 RESOLVED Incident Policy Document Issue Opened 2025-06-17 · Closed 2025-07-16 · 98% similar
Sectigo: Lack of technical controls for multiparty control access to Secure Zone
#1954580 RESOLVED Incident Revocation Issue Opened 2025-03-17 · Closed 2025-05-16 · 97% similar
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
#1985307 RESOLVED Incident Opened 2025-08-26 · Closed 2025-10-09 · 97% similar
Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 90% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 90% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1946927 RESOLVED Incident Certificate Misissuance Opened 2025-02-08 · Closed 2025-05-16 · 89% similar
Sectigo: Intermittent OCSP unauthorized responses for certificates older than 15 minutes

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action