← Sectigo cases
Bugzilla #2061907 Ca Certificate Compliance Incident Problem Reporting Failure Information Request Opened By Researcher

Sectigo complaint about non-response to a court-related request for validation records

RESOLVED INVALID Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns a third-party complaint about Sectigo’s handling of a request for validation evidence related to a DV TLS certificate for www.TradingExpertView.com issued on 2024-03-07. The reporter said a formal demand was sent on 2025-09-10 and later argued that Sectigo and WebPros failed to respond to a lawful court request. Sectigo replied that it had not initially found any record of the request, said the certificate’s issuance and DCV were performed by Sectigo, and stated that detailed validation records are only provided to limited external parties. After the reporter provided proof of delivery, Sectigo said it located a delivery scanned into its system on 2025-09-22, but concluded the document was a Request for Production addressed to WebPros International and that no action by Sectigo was required because Sectigo was not a party to the lawsuit. Mozilla stated that the Baseline Requirements require retention of DCV records and availability to auditors and other authorized parties, but do not require disclosure to any requesting relying party, and said the available information did not establish an actionable violation. The bug was resolved INVALID.

Model: gpt-5.4-mini Generated: 2026-08-10 11:45 UTC Revised: 2026-08-30 07:01 UTC Confidence: 0.93 11 comments
Chronology
  1. Sectigo issued a DV TLS certificate for www.TradingExpertView.com.
  2. A formal demand was sent requesting the validation evidence used for DCV of the certificate.
  3. Sectigo later said it scanned a delivery addressed to WebPros International into its system.
Thread Activity
  1. Community commenter — The reporter opened a preliminary incident report alleging refusal to produce DCV validation evidence and cited BR §§5.4.1 and 5.4.3.
  2. Sectigo — Sectigo disputed the claims, said it was preparing a response, and said it believed the bug should be closed INVALID.
  3. Sectigo — Sectigo said it found no record of the request, stated that Sectigo performed issuance and DCV itself, and said specific validation details are only provided to limited external parties.
  4. Community commenter — The reporter added evidence attachments and said the formal demand was sent to Sectigo’s General Counsel and others.
  5. Mozilla representative — Mozilla said the BRs require retention and availability of validation records to auditors and other authorized parties, but not to any requesting relying party, and proposed closing the bug as INVALID.
  6. Community commenter — The reporter argued that Sectigo and WebPros failed to respond to a lawful court request and said proof of delivery was attached.
  7. Sectigo — Sectigo said it located a delivery scanned on 2025-09-22, concluded it was a Request for Production addressed to WebPros International, and said no action by Sectigo was required.
Participants
Community commenter Sectigo Mozilla representative
External References
Similar Local Cases
#2062162 RESOLVED Problem Reporting Failure Incident Externally Reported Incident Opened By Subscriber Or Relying Party Opened 2026-08-10 · Closed 2026-08-31 · 78% similar
HARICA: TLS server certificate issuance against CP/CPS
#1733000 RESOLVED Ca Certificate Compliance Incident Policy Document Issue Cp Cps Document Opened 2021-09-28 · Closed 2023-02-22 · 74% similar
QuoVadis: revocation services validity set to expected value plus one second
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 74% similar
Sectigo: Incorrect OCSP responses
#1793787 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Repository Issue Opened 2022-10-05 · Closed 2023-02-22 · 73% similar
Sectigo: Non-existent hostname in CDP and AIA URLs
#2055539 RESOLVED Problem Reporting Failure Incident Externally Reported Incident Revocation Issue Opened 2026-07-16 · Closed 2026-08-11 · 71% similar
DigiCert: Delayed availability of OCSP responses
#2047952 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Problem Reporting Failure Opened 2026-06-16 · Closed 2026-08-04 · 70% similar
KIR: OCSP responder does not return status for precertificate
#2050274 RESOLVED Incident Ccadb Disclosure Issue Problem Reporting Failure Remediation Tracking Opened 2026-06-24 · Closed 2026-08-04 · 69% similar
FNMT: Delay in incident disclosure reporting for Bug 2049012
#2048995 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Problem Reporting Failure Opened 2026-06-19 · Closed 2026-07-30 · 69% similar
eMudhra emSign PKI Services: OCSP Responder Returned "Unauthorized" for Some Pecertificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

⚠

Confirm action