← SSL.com cases
Bugzilla #1534145 Certificate Misissuance

SSL.com: P-384 curve / ecdsa-with-SHA256 certificates

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com disclosed that it had issued a limited number of ECDSA certificates using a curve-hash pair that is no longer allowed by the Mozilla Root Store Policy. The issue specifically involved certificates issued with the P-384 curve / ecdsa-with-SHA256 pair, which the incident report states is not permitted under Mozilla Root Store Policy section 5.1 (which allows P-384 with SHA-384). SSL.com said it became aware of the problem during a manual review of certificates that were going to be issued on 25 February 2019, and that the investigation found additional certificates had been issued using the same illegal curve-hash pair, including several CA certificates. SSL.com suspended ECDSA issuance, contacted Mozilla, and began remediation, including reviewing Mozilla technical requirements and implementing linters to improve pre-issuance and post-issuance auditing. SSL.com modified production CA configuration to prevent future issuance with these parameters, revoked misissued end-user certificates, and also decided to revoke associated CAs (including those created before the policy change) while resuming ECDSA issuance after fixing certificate profiles. The bug was resolved as FIXED, and a later comment stated that remediation was completed and there appeared to be no questions on the incident report.

Model: gpt-5.4-nano Generated: 2026-06-13 18:06 UTC Revised: 2026-06-16 18:35 UTC Confidence: 0.90 2 comments
Chronology
  1. Mozilla Root Store Policy version 2.4 was published, limiting allowed ECDSA curve-hash pairs.
  2. SSL.com identified that some certificates being reviewed for issuance used an illegal ECDSA curve-hash pair (P-384 with SHA-256).
  3. SSL.com suspended ECDSA issuance and began remediation, contacting Mozilla and implementing policy requirement linters.
  4. SSL.com updated production CA configurations, revoked misissued end-user certificates, revoked associated CAs, and resumed ECDSA issuance.
Thread Activity
  1. Fastly representative — Posted an incident report describing SSL.com’s issuance of P-384/ecdsa-with-SHA256 certificates, the discovery during internal review, and the remediation steps including suspension, linters, configuration changes, and revocations.
  2. Fastly representative — Commented that all remediation had been completed and that there appeared to be no questions on the incident report.
Participants
Fastly representative Community commenter
External References
Similar Local Cases
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 83% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1850171 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-08-25 · Closed 2023-09-29 · 80% similar
SSL.com: S/MIME certificates issued prior to validation
#1961406 RESOLVED Certificate Misissuance Opened 2025-04-18 · Closed 2025-07-02 · 80% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 79% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 79% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1532436 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-03-04 · Closed 2023-02-22 · 71% similar
Chunghwa Telecom: Test certificate with unregistered domain name
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 70% similar
Izenpe: Multiple invalid EV certificates issued
#1497703 RESOLVED Self Reported Incident Certificate Misissuance Closure Request Opened 2018-10-09 · Closed 2023-02-22 · 69% similar
SECOM: Undisclosed intermediate certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action