← Sectigo cases
Bugzilla #2048370 Self Reported Incident Delayed Revocation Remediation Tracking Opened By Ca

Sectigo incident report closed after OCSP response signing delays from certstatus-manager restart loop

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo’s incident report concerns delays in signing OCSP responses for some newly issued certificates after its certstatus-manager application repeatedly restarted. Sectigo said the restart loop began on 2026-06-13, was resolved on 2026-06-15, and that the backlog in its OCSP refresher signing process delayed some previously failed initial signings beyond the required 15 minutes. The company reported that it received a support ticket and a Certificate Problem Report on 2026-06-17, then completed its action items and requested closure. Sectigo’s closure summary said the root cause was a bug in its storage environment that cascaded into the restart loop and refresher backlog. The bug was marked RESOLVED with resolution FIXED. No external closure action is described in the thread beyond the final call for comments and the planned closure date.

Model: gpt-5.4-mini Generated: 2026-06-19 19:44 UTC Revised: 2026-08-09 06:01 UTC Confidence: 0.96 5 comments
Chronology
  1. certstatus-manager restart loop began, causing OCSP signing backlog
  2. restart loop was resolved
  3. Sectigo received a support ticket and a CPR about “unauthorized” OCSP responses
  4. some newly issued certificates had OCSP responses that were not signed within the required timeframe
  5. Sectigo said all action items were completed and requested closure
Thread Activity
  1. Sectigo — Posted a preliminary incident report describing the restart loop, the OCSP signing backlog, and the CPR about “unauthorized” OCSP responses.
  2. Sectigo — Posted the full incident report with timeline, impact, and explanation of the refresher backlog delaying signing for some newly issued certificates.
  3. Sectigo — Requested a next update date of 2026-07-31 while remaining action items were still open.
  4. Sectigo — Stated that all action items had been completed and requested closure of the incident report.
  5. CCADB representative — Posted a final call for comments or questions and said the report would be closed around 2026-08-07.
Participants
Sectigo CCADB representative
External References
Similar Local Cases
#2054098 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Remediation Tracking Opened 2026-07-10 · Closed 2026-09-02 · 99% similar
Sectigo: Incorrect jurisdictionStateOrProvinceName attribute value in Code Signing certificate
#2069636 ASSIGNED Ca Documents Incident Self Reported Incident Policy Document Issue Opened 2026-09-05 Still Open · 89% similar
Sectigo: CP/CPS language involving extendedKeyUsage found to be subject to multiple interpretations
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 89% similar
Sectigo: Incorrect OCSP responses
#2069640 ASSIGNED Ca Certificate Compliance Self Reported Incident Opened By Ca Opened 2026-09-05 Still Open · 87% similar
Sectigo: No revocation after CP/CPS language involving extendedKeyUsage found to be subject to multiple interpretations
#1793787 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Repository Issue Opened 2022-10-05 · Closed 2023-02-22 · 87% similar
Sectigo: Non-existent hostname in CDP and AIA URLs
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 86% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 86% similar
Sectigo: Incorrect JOI for federal credit unions
#2033000 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-04-17 · Closed 2026-07-09 · 82% similar
SwissSign: Certificate Profile error for S/MIME MV

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action