certSIGN: certificates with delayed SCT signature (notBefore outside 48-hour window)
certSIGN reported a compliance incident involving TLS subscriber certificates whose notBefore values appeared to be more than 48 hours earlier than the effective signing operation when interpreted from the last embedded SCT timestamp. The issue was identified during investigation after the Chrome Root Program reported a potential non-compliance for one certificate; certSIGN then found a total of 14 affected subscriber certificates (7 still valid at the time of reporting). certSIGN stated that the incident did not stop certificate issuing because it was determined to be related to CT logging timing controls and did not affect validation procedures, certificate contents, or key material. certSIGN’s remediation included deploying a patch to fix the CT logging timing behavior and updating its linter for SCT delay validation, and it revoked the non-conformant certificates. The report closure summary states the root causes as a lack of an upper time boundary in CT logging retry logic aligned with BR 7.1.2.7 and a lack of delay checks in the linter. The bug is marked RESOLVED with resolution FIXED, and the CCADB incident reporting process indicates a final call for comments before closure on approximately 2026-03-30.
- Non-compliance period began (effective date for applying the Certificate Profiles Update).
- Chrome Root Program reported a potential non-compliance for one certificate; certSIGN began investigation and notified the relevant DRA.
- certSIGN opened Bugzilla ticket 2016672 with a preliminary incident report.
- certSIGN deployed a patch to fix the issue and prevent future delays.
- certSIGN revoked the valid non-conformant certificates.
- certSIGN submitted the report closure summary and requested closure.
- certSIGN — Posted a preliminary incident report stating that investigation found seven leaf certificates with notBefore exceeding the 48-hour window and that the certificates would be revoked.
- Sectigo — Noted that ctlint could check this and added a lint with a link to a pull request and an example crt.sh query.
- Sectigo — Referenced a corresponding idea in Zlint and provided a link to a zlint pull request.
- certSIGN — Posted the full incident report describing 14 affected subscriber certificates, the BR 7.1.2.7 notBefore requirement, the disclosure source, and the timeline including patch deployment and revocation.
- certSIGN — Reported that certSIGN completed linter tests for SCT delay validations in February 2026.
- Community commenter — Reminded the CA about CCADB incident reporting guidelines, including weekly updates and closure report requirements.
- certSIGN — Submitted a report closure summary stating the incident details, root causes, remediation (revocation and linter update), and requested closure.
- CCADB representative — Issued a final call for comments and stated the incident would be closed on approximately 2026-03-30.