Sectigo: Refusal to produce validation evidence for DV certificate issued via cPanel/WebPros subordinate CA (www.TradingExpertView.com, 2024-03-07)
Categories
(CA Program :: CA Certificate Compliance, enhancement)
Tracking
(Not tracked)
People
(Reporter: frank2_williams, Unassigned)
Details
Attachments
(1 file)
|
1.16 MB,
application/pdf
|
Details |
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36
Actual results:
Summary (Subject Line)
Sectigo: Refusal to produce validation evidence for DV certificate issued via cPanel/WebPros subordinate CA (www.TradingExpertView.com, 2024-03-07)
Description
Preliminary Incident Report
Summary
-
Incident description:
On or about March 7, 2024, Sectigo Limited issued a Domain Validation (DV) TLS certificate forwww.TradingExpertView.comthrough a cPanel (WebPros International, LLC) subordinate CA. The certificate was issued under Sectigo's publicly trusted root program. On September 10, 2025, the undersigned submitted a formal demand to Sectigo and WebPros requesting production of the validation evidence used to satisfy Domain Control Validation (DCV) for this certificate, as required by the CA/Browser Forum Baseline Requirements. As of August 6, 2026 — more than 25 months after the formal demand — Sectigo and/or WebPros have refused to produce the requested validation evidence. This refusal constitutes a violation of BR §5.4.1 (Audit Logging) and §5.4.3 (Retention and Availability of Audit Logs), and undermines the integrity of the Web PKI by preventing independent verification that the certificate was issued to the legitimate domain controller. The incident also raises concerns under BR §3.2 (Identity Verification) regarding whether proper validation was performed at all. -
Relevant policies:
- CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, v2.0.0 (and subsequent versions):
- §3.2 — Verification of Identity
- §5.4.1 — Audit Logging
- §5.4.3 — Retention and Availability of Audit Logs
- Mozilla Root Store Policy
- Google Chrome Root Program Policy
- Apple Root Certificate Program
- Microsoft Trusted Root Program Requirements
- CA/Browser Forum Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, v2.0.0 (and subsequent versions):
-
Source of incident disclosure:
Third-party reporter (affected party / security researcher).
Affected Certificate Details
| Field | Value |
|---|---|
| Domain(s) | www.TradingExpertView.com |
| Certificate Type | DV TLS Server Certificate |
| Issuing CA | Sectigo Limited (via cPanel / WebPros subordinate CA) |
| Approximate Issuance Date | March 7, 2024 |
| CT Log Entry | ID = 12440271876: CT log URL or SCT details] |
| Certificate Fingerprint (SHA-256) | [ E19C71ADC44BFB6FF15F4C5C78FDB4F752178B012EA28916BE3DC8393A8146F5 ] |
| Serial Number | [86:69:67:14:f8:23:bf:f7:a0:56:eb:f9:9a:0a:7a:26] |
Timeline
All times are UTC.
- 2024-03-07 (approx.) — Sectigo Limited, acting through its cPanel (WebPros) subordinate CA, issues a DV TLS certificate for
www.TradingExpertView.com. - 2025-9-10 — Formal demand sent to Sectigo and/or WebPros requesting production of validation evidence (DCV logs, method used, timestamps, and personnel involved) pursuant to BR §5.4.1 and §5.4.3. [Attached demand letter/correspondences.]
- 2025-9-10 through 2026-08-06 — Repeated follow-up requests for the validation evidence. Sectigo and/or WebPros have failed and/or refused to produce the requested documentation.
- 2026-08-06 — As of this date, no validation evidence has been provided. This report is filed to request a compliance review by the root store operators.
Nature of the Violation
1. BR §5.4.1 — Audit Logging
Baseline Requirements §5.4.1 states:
"The CA SHALL record all certificate management activities, including: … the information validated, the validation method used, the date and time of the validation, and the personnel involved in the validation."
Sectigo / WebPros have failed to produce these records upon formal request, suggesting either (a) the records were never created, (b) the records were improperly maintained, or (c) the CA is willfully withholding evidence of its validation practices.
2. BR §5.4.3 — Retention and Availability of Audit Logs
Baseline Requirements §5.4.3 states:
"Audit logs SHALL be retained for at least two (2) years … and SHALL be made available to auditors, root store operators, and other authorized parties upon request."
The certificate was issued in March 2024. The formal demand was made in July 2024, well within the two-year retention window. The refusal to produce these logs more than 25 months after the demand constitutes a clear violation of the retention and availability obligations.
3. BR §3.2 — Verification of Identity
Because Sectigo / WebPros have refused to produce validation evidence, there is no independently verifiable proof that the domain control validation for www.TradingExpertView.com was performed in accordance with BR §3.2. The inability to verify DCV undermines trust in the certificate's legitimacy.
Delegation and Accountability
Sectigo delegated DV validation and issuance functions to cPanel / WebPros International, LLC through a subordinate CA arrangement. Under all major root program policies — Mozilla, Google Chrome, Apple, and Microsoft — the root CA (Sectigo) retains ultimate accountability for the actions of its subordinate CAs and delegated validation agents. Sectigo cannot absolve itself of compliance responsibility by pointing to its delegate.
Additional Context
The certificate at issue was used in connection with a trading platform at www.TradingExpertView.com. The reporter alleges that the certificate may have facilitated impersonation of a legitimate trading platform, with potential implications under:
- SEC Rule 10b-5 (anti-fraud)
- SEC Regulation S-P, Section 4.2 (Cybersecurity Guidelines)
These regulatory concerns are noted for context; the primary purpose of this report is to address the Web PKI compliance failures (BR §§3.2, 5.4.1, 5.4.3) that prevent independent verification of the certificate's legitimacy.
Requested Actions
- Compliance Review: Request that Mozilla, Google Chrome, Apple, and Microsoft root program operators review Sectigo's (and WebPros's) compliance with BR §§3.2, 5.4.1, and 5.4.3.
- Production of Evidence: Direct Sectigo to produce the validation evidence for the March 7, 2024 certificate issuance to
www.TradingExpertView.com, including:- The DCV method used (e.g., HTTP-01, DNS-01, email)
- The exact validation token or response
- Date/time stamps of validation
- Identity of the personnel or automated system performing validation
- Audit of Delegated Practices: Review whether Sectigo's delegation of DV validation to WebPros includes adequate controls to ensure BR compliance and evidence retention.
- Remediation: Require Sectigo and WebPros to implement processes ensuring that validation evidence is retained and producible upon request for the full BR-mandated retention period.
Attachments
- [ ] Formal demand letter dated September 10, 2025
- [ ] All correspondence with Sectigo / WebPros regarding this request
- [ ] CT log entry for the affected certificate
- [ ] Certificate PEM/DER or fingerprint details
- [ ] Summons IN THE 21ST JUDICIAL CIRCUIT, ST. LOUIS COUNTY, MISSOURI
Reporter Contact
Email: digitariosx.0@gmail.com
Expected results:
Sectigo: Should have produced validation evidence for DV certificate issued via cPanel/WebPros subordinate CA (www.TradingExpertView.com, 2024-03-07)
Comment 1•2 hours ago
|
||
Sectigo disputes the claims within this report. We are currently preparing a response that will go into the details of this case as we understand them. We believe this bug should ultimately be closed with Resolution INVALID.
Since we do not consider this an incident, our response will not use the CCADB Full Incident Template. Instead, we will directly answer the claims made by what comment 0 calls a ”Preliminary Incident Report”. These answers will be posted within the next few days.
Description
•