← Sectigo cases
Bugzilla #2019995
Certificate Problem Report
Sectigo: Package patching gap within Certificate Systems
RESOLVED
FIXED
Sectigo
AI Summary
Sectigo reported a gap in their package patching process, identified during an internal audit. A critical severity operating system package was not upgraded across multiple servers, leading to a non-compliance period from June 2025 to February 2026. The root causes included unclear ownership of process verification and insufficient reinforcement of existing patching procedures. Sectigo has since completed remediation actions, including refining process documentation and enhancing monitoring for critical patches.
Chronology
- Non-compliance start date
- Non-compliance identified date
- Non-compliance end date
- Report closure summary provided
Participants
Martijn Katerbarg
External References
Similar Local Cases
Sectigo: Incomplete Subject organizationName
Sectigo: Late receipt and disclosure to CCADB of ETSI audit letters
Sectigo: S/MIME certificates with (null) string value in subject attributes
Sectigo: Intermittent OCSP unauthorized responses for certificates older than 15 minutes
Sectigo: Lack of documentation for vulnerability NVD rating adjustment
Sectigo: Failure to reply to Certificate Problem Reports within 24 hours
Sectigo: Certificate issuance delayed for more than 398 days after DCV was completed
Sectigo: Temporary unavailability for subset of CRLs