← Sectigo cases
Bugzilla #2048370 Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Problem Reporting Failure

Sectigo incident report: OCSP response signing delays caused by certstatus-manager restart loop

ASSIGNED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported an incident involving delays in signing OCSP responses for some newly issued certificates after its certstatus-manager application began restarting repeatedly. The company said it first noticed spikes in its OCSP replication system on 2026-06-15 and later received a support ticket and a Certificate Problem Report on 2026-06-17 about “unauthorized” OCSP responses. Sectigo’s investigation found that some OCSP responses had been signed by its HSMs but did not make it to publication, and that its OCSP refresher signing backstop had accumulated backlog because of the restart loop. In the full report, Sectigo said the non-compliance began on 2026-06-13 and ended on 2026-06-17, and that the issue affected the timely signing of OCSP responses for a small number of newly issued certificates. Sectigo later stated that all action items had been completed and requested closure of the incident report. The bug remains ASSIGNED and a final call for comments was posted on 2026-07-31.

Model: gpt-5.4-mini Generated: 2026-06-19 19:44 UTC Revised: 2026-08-02 07:01 UTC Confidence: 0.93 5 comments
Chronology
  1. certstatus-manager restart loop began, creating OCSP signing backlog
  2. restart loop was resolved, but some newly issued certificates had already experienced OCSP signing delays
  3. Sectigo received a support ticket and a CPR about “unauthorized” OCSP responses
  4. Sectigo identified that some OCSP responses for newly issued certificates had not been signed successfully
  5. Sectigo said all action items were completed and requested closure
Thread Activity
  1. Sectigo — Filed a preliminary incident report describing the certstatus-manager restart loop, the OCSP signing backlog, and the CPR about “unauthorized” OCSP responses.
  2. Sectigo — Posted the full incident report with timeline, impact, and explanation that the refresher backlog delayed signing for some newly issued certificates.
  3. Sectigo — Requested a next update date of 2026-07-31 while remaining action items were still open.
  4. Sectigo — Stated that all action items had been completed and requested closure of the incident report.
  5. CCADB representative — Posted a final call for comments or questions and said the report would be closed around 2026-08-07.
Participants
Sectigo CCADB representative
External References
Similar Local Cases
#1954580 RESOLVED Incident Revocation Issue Opened 2025-03-17 · Closed 2025-05-16 · 98% similar
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 97% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 95% similar
Sectigo: Incorrect JOI for federal credit unions
#2054098 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-10 Still Open · 89% similar
Sectigo: Incorrect jurisdictionStateOrProvinceName attribute value in Code Signing certificate
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 89% similar
Sectigo: Incorrect OCSP responses
#1994454 RESOLVED Problem Reporting Failure Opened 2025-10-15 · Closed 2025-12-11 · 89% similar
Sectigo: Failure to reply to Certificate Problem Reports within 24 hours
#2000277 RESOLVED Incident Opened 2025-11-14 · Closed 2025-12-19 · 88% similar
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA
#2033170 RESOLVED Ca Security Vulnerability Incident Self Reported Incident Revocation Issue Opened 2026-04-18 · Closed 2026-07-20 · 88% similar
DigiCert: Misissued code signing certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action