← certSIGN cases
Bugzilla #2016672 Incident Revocation Issue

certSIGN: certificates with delayed SCT signature (notBefore outside 48-hour window)

RESOLVED FIXED certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

certSIGN reported a compliance incident involving TLS subscriber certificates whose notBefore values appeared to be more than 48 hours earlier than the effective signing operation when interpreted from the last embedded SCT timestamp. The issue was identified during investigation after the Chrome Root Program reported a potential non-compliance for one certificate; certSIGN then found a total of 14 affected subscriber certificates (7 still valid at the time of reporting). certSIGN stated that the incident did not stop certificate issuing because it was determined to be related to CT logging timing controls and did not affect validation procedures, certificate contents, or key material. certSIGN’s remediation included deploying a patch to fix the CT logging timing behavior and updating its linter for SCT delay validation, and it revoked the non-conformant certificates. The report closure summary states the root causes as a lack of an upper time boundary in CT logging retry logic aligned with BR 7.1.2.7 and a lack of delay checks in the linter. The bug is marked RESOLVED with resolution FIXED, and the CCADB incident reporting process indicates a final call for comments before closure on approximately 2026-03-30.

Model: gpt-5.4-nano Generated: 2026-06-13 21:35 UTC Revised: 2026-06-16 18:25 UTC Confidence: 0.90 10 comments
Chronology
  1. Non-compliance period began (effective date for applying the Certificate Profiles Update).
  2. Chrome Root Program reported a potential non-compliance for one certificate; certSIGN began investigation and notified the relevant DRA.
  3. certSIGN opened Bugzilla ticket 2016672 with a preliminary incident report.
  4. certSIGN deployed a patch to fix the issue and prevent future delays.
  5. certSIGN revoked the valid non-conformant certificates.
  6. certSIGN submitted the report closure summary and requested closure.
Thread Activity
  1. certSIGN — Posted a preliminary incident report stating that investigation found seven leaf certificates with notBefore exceeding the 48-hour window and that the certificates would be revoked.
  2. Sectigo — Noted that ctlint could check this and added a lint with a link to a pull request and an example crt.sh query.
  3. Sectigo — Referenced a corresponding idea in Zlint and provided a link to a zlint pull request.
  4. certSIGN — Posted the full incident report describing 14 affected subscriber certificates, the BR 7.1.2.7 notBefore requirement, the disclosure source, and the timeline including patch deployment and revocation.
  5. certSIGN — Reported that certSIGN completed linter tests for SCT delay validations in February 2026.
  6. Community commenter — Reminded the CA about CCADB incident reporting guidelines, including weekly updates and closure report requirements.
  7. certSIGN — Submitted a report closure summary stating the incident details, root causes, remediation (revocation and linter update), and requested closure.
  8. CCADB representative — Issued a final call for comments and stated the incident would be closed on approximately 2026-03-30.
Participants
certSIGN Sectigo Community commenter CCADB representative
Similar Local Cases
#2033170 RESOLVED Ca Security Vulnerability Incident Self Reported Incident Revocation Issue Opened 2026-04-18 · Closed 2026-07-20 · 86% similar
DigiCert: Misissued code signing certificates
#2009491 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Repository Issue Opened 2026-01-09 · Closed 2026-02-17 · 86% similar
DigiCert: Several non-functioning AIA URLs
#2001327 RESOLVED Incident Revocation Issue Opened 2025-11-20 · Closed 2026-01-05 · 84% similar
NETLOCK: Missing CDP Disclosure in CCADB
#1972887 RESOLVED Self Reported Incident Revocation Issue Opened 2025-06-18 · Closed 2025-09-30 · 84% similar
A-Trust: TLS non-compliance detected during linter implementation
#2033412 RESOLVED Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Opened 2026-04-20 · Closed 2026-06-25 · 78% similar
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)
#1950574 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2025-02-26 · Closed 2025-09-15 · 78% similar
SECOM: S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#1954580 RESOLVED Incident Revocation Issue Opened 2025-03-17 · Closed 2025-05-16 · 77% similar
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 77% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action