Sectigo incident report closed after OCSP response signing delays from certstatus-manager restart loop
Sectigo’s incident report concerns delays in signing OCSP responses for some newly issued certificates after its certstatus-manager application repeatedly restarted. Sectigo said the restart loop began on 2026-06-13, was resolved on 2026-06-15, and that the backlog in its OCSP refresher signing process delayed some previously failed initial signings beyond the required 15 minutes. The company reported that it received a support ticket and a Certificate Problem Report on 2026-06-17, then completed its action items and requested closure. Sectigo’s closure summary said the root cause was a bug in its storage environment that cascaded into the restart loop and refresher backlog. The bug was marked RESOLVED with resolution FIXED. No external closure action is described in the thread beyond the final call for comments and the planned closure date.
- certstatus-manager restart loop began, causing OCSP signing backlog
- restart loop was resolved
- Sectigo received a support ticket and a CPR about “unauthorized” OCSP responses
- some newly issued certificates had OCSP responses that were not signed within the required timeframe
- Sectigo said all action items were completed and requested closure
- Sectigo — Posted a preliminary incident report describing the restart loop, the OCSP signing backlog, and the CPR about “unauthorized” OCSP responses.
- Sectigo — Posted the full incident report with timeline, impact, and explanation of the refresher backlog delaying signing for some newly issued certificates.
- Sectigo — Requested a next update date of 2026-07-31 while remaining action items were still open.
- Sectigo — Stated that all action items had been completed and requested closure of the incident report.
- CCADB representative — Posted a final call for comments or questions and said the report would be closed around 2026-08-07.