Sectigo self-reported CP/CPS ambiguity in extendedKeyUsage language after third-party CPR
Sectigo opened this bug after receiving a Certificate Problem Report about language in Section 7.1.2.3 of its TLS CP/CPS. Sectigo says it believes certificates were issued according to the intended meaning of the language, but community feedback showed the text could be interpreted in multiple ways and some participants considered it an incident. Sectigo opened the bug to document the issue, track root causes and action items, and support community review. Sectigo also said it was preparing a Full Incident Report. The thread states that the source of the disclosure was a third-party report, but the bug was opened by Sectigo itself to disclose and track the issue.
- Sectigo received a Certificate Problem Report about Section 7.1.2.3 of its TLS CP/CPS.
- Sectigo opened Mozilla bug 2061902 to discuss the issue with the community.
- Sectigo opened this bug to document the issue and prepare a Full Incident Report.
- Sectigo — Sectigo filed a preliminary incident report describing the CP/CPS ambiguity, the prior CPR, the community discussion, and its plan to prepare a Full Incident Report.