Sectigo: Partial OCSP response publication delay for newly issued certificates
Sectigo reported an OCSP compliance issue affecting newly issued certificates. On April 9, 2026 at 21:30 UTC, a Certificate Problem Report was received stating that a number of certificates returned an “Unauthorized” OCSP response more than 15 minutes after issuance of the pre-certificate. Sectigo investigated and determined the behavior was caused by a database replication delay in its US datacenter, where CertStatus serves OCSP/CRL data using both US and UK datacenters and a CDN. As a precaution, Sectigo disabled the CertStatus Web nodes responsible for responding to OCSP requests on the US side until mitigation was in place. For remediation, Sectigo extended its CertStatus-Web application so each node targets all replica databases in both datacenter sites while preferring the local datacenter, and it disfavours databases more than 10 minutes out of sync. The bug was resolved as FIXED, with the report closure summary stating that the action items were completed as described and requesting closure.
- Sectigo received a Certificate Problem Report about “Unauthorized” OCSP responses more than 15 minutes after pre-certificate issuance.
- Sectigo disabled CertStatus-Web nodes on the US side as a precaution while investigating the replication delay.
- Sectigo discussed mitigation options and decided to improve OCSP handling within its CDN.
- Sectigo reported remediation completion via updated CertStatus-Web logic and requested incident report closure.
- Sectigo — Opened a preliminary incident report stating a third-party Certificate Problem Report was received and that the issue had resolved automatically while further investigation and monitoring continued.
- Sectigo — Provided a full incident report attributing the issue to US datacenter database replication delay and stating CertStatus-Web US nodes were disabled as a precaution.
- Sectigo — Requested a next update for 2026-05-31 while working on action items.
- Sectigo — Submitted a report closure summary with root cause and remediation details (extended CertStatus-Web to target replicas across both datacenters and disprefer replicas more than 10 minutes out of sync) and requested closure.
- CCADB representative — Issued a final call for comments and indicated the incident report would be closed around 2026-06-05 if no questions were raised.