← Sectigo cases
Bugzilla #2069636 Ca Certificate Compliance Incident Self Reported Incident Information Request Opened By Ca

Sectigo self-reported CP/CPS ambiguity in extendedKeyUsage language after third-party CPR

NEW Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo opened this bug after receiving a Certificate Problem Report about language in Section 7.1.2.3 of its TLS CP/CPS. Sectigo says it believes certificates were issued according to the intended meaning of the language, but community feedback showed the text could be interpreted in multiple ways and some participants considered it an incident. Sectigo opened the bug to document the issue, track root causes and action items, and support community review. Sectigo also said it was preparing a Full Incident Report. The thread states that the source of the disclosure was a third-party report, but the bug was opened by Sectigo itself to disclose and track the issue.

Model: gpt-5.4-mini Generated: 2026-09-06 11:00 UTC Confidence: 0.93 1 comment
Chronology
  1. Sectigo received a Certificate Problem Report about Section 7.1.2.3 of its TLS CP/CPS.
  2. Sectigo opened Mozilla bug 2061902 to discuss the issue with the community.
  3. Sectigo opened this bug to document the issue and prepare a Full Incident Report.
Thread Activity
  1. Sectigo — Sectigo filed a preliminary incident report describing the CP/CPS ambiguity, the prior CPR, the community discussion, and its plan to prepare a Full Incident Report.
Participants
Sectigo
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#2048370 RESOLVED Self Reported Incident Delayed Revocation Remediation Tracking Opened By Ca Opened 2026-06-17 · Closed 2026-08-08 · 89% similar
Sectigo: Delay in some OCSP response signing due to application restart loop
#2069640 NEW Ca Certificate Compliance Self Reported Incident Incident Opened By Ca Opened 2026-09-05 Still Open · 88% similar
Sectigo: No revocation after CP/CPS language involving extendedKeyUsage found to be subject to multiple interpretations
#1741026 RESOLVED Ca Certificate Compliance Revocation Issue Self Reported Incident Opened 2021-11-13 · Closed 2023-02-22 · 87% similar
Sectigo: Incorrect JOI for federal credit unions
#1650845 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-07-06 · Closed 2024-06-30 · 87% similar
Sectigo: CPR response issues
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 86% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1736064 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-10-15 · Closed 2023-02-22 · 85% similar
Sectigo: Subject field with unvalidated information included in certificates
#1563579 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-07-04 · Closed 2023-02-22 · 85% similar
Sectigo: Failure to provide timely incident reports
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 80% similar
Sectigo: Incorrect OCSP responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action