← certSIGN cases
Bugzilla #2016672
Certificate Problem Report
certSIGN: certificates with delayed SCT signature
RESOLVED
FIXED
certSIGN
AI Summary
certSIGN identified a compliance issue involving 14 subscriber certificates that had a 'notBefore' value exceeding the 48-hour limit set by the Baseline Requirements. This issue was reported by the Chrome Root Program, leading to an internal investigation. The affected certificates were subsequently revoked, and certSIGN implemented updates to their linter to prevent future occurrences. The root cause was linked to a lack of logging limits for CT logs and insufficient checks in the linter for SCT delays.
Chronology
- Effective date for applying the Certificate Profiles Update.
- Chrome Root Program reported potential non-compliance.
- certSIGN opened Bugzilla ticket #2016672 with the Preliminary Incident Report.
- certSIGN revoked the valid non-conformant certificates.
Participants
Gabriel PETCU
Rob Sectigo
External References
Similar Local Cases
certSIGN: Missing certificate from the list of bad order subject attributtes
certSIGN: delay in updating a Bugzilla ticket
certSIGN: Certificates with incorrect Subject attribute order
certSIGN: Incorrect data in stateOrProvinceName
certSIGN: Delayed revocation
certSIGN: Delayed response to CPR
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #4 – Expired cert with bad order of attributes
ACCV: Certificates issued with Policy qualifiers other than id-qt-cps