← Sectigo cases
Bugzilla #2019995 Ca Certificate Compliance

Sectigo: Package patching gap within Certificate Systems

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a compliance incident discovered through its internal audit process: a gap in package patching within its Certificate Systems. The incident involved an operating system package with Critical severity that was not upgraded across multiple servers, including three K3S servers, within the required timeframe. Sectigo stated that it opened and tracked patching tickets in June 2025, with the Critical severity patch expected by 2025-06-13 but completed later. Sectigo completed patching of the affected CA Systems on 2026-02-27 and provided a root cause analysis citing insufficiently defined ownership/accountability, insufficient reinforcement of existing processes, and lack of effective verification controls. For remediation, Sectigo refined process documentation, implemented monitoring with automated notifications for critical patching tickets, and completed additional staff training, and it also planned to review and update patching practices and policies. The report closure summary states that all disclosed action items were completed as described and requests closure, with a final call for comments indicating closure on approximately 2026-04-08. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:55 UTC Revised: 2026-06-16 19:05 UTC Confidence: 0.90 5 comments
Chronology
  1. Critical-severity package patching was due for Certificate Systems but was not completed by the required time.
  2. Sectigo’s internal audit identified the patching failure for Certificate Systems.
  3. Sectigo completed patching of the affected CA Systems.
  4. Sectigo reported remediation completion and requested closure of the incident report.
Thread Activity
  1. Sectigo — Opened a preliminary incident report stating an internal audit found a gap in package patching and that at least one package across Kubernetes hosts was not patched/remediated within the required timeframe.
  2. Sectigo — Submitted a full incident report with a timeline, stating a Critical-severity OS package was not upgraded across multiple servers and providing root cause analysis.
  3. Sectigo — Requested a next update for 2026-04-10 while working on action items.
  4. Sectigo — Reported action items as completed, described remediation steps (process documentation, monitoring/automated notifications, and staff training), and requested closure.
  5. CCADB representative — Issued a final call for comments and noted the incident report would be closed on approximately 2026-04-08.
Participants
Sectigo CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 88% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1724458 RESOLVED Ca Certificate Compliance Opened 2021-08-06 · Closed 2023-02-22 · 88% similar
Sectigo: Mojibake in certificate Subject fields
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 87% similar
Sectigo: Incorrect JOI for federal credit unions
#1793789 RESOLVED Ca Certificate Compliance Opened 2022-10-05 · Closed 2023-02-22 · 86% similar
Sectigo: Incorrect JOI
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 80% similar
Sectigo: Failure to provide timely incident reports
#1518553 RESOLVED Ca Certificate Compliance Opened 2019-01-08 · Closed 2023-02-22 · 79% similar
Sectigo: Use of forbidden subjectPublicKeyInfo algorithm
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 78% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1597950 RESOLVED Ca Certificate Compliance Incident Opened 2019-11-20 · Closed 2023-02-22 · 78% similar
Sectigo: CCADB failed ALV - Ensured Root CA

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action