← SSL.com cases
Bugzilla #1579509 Incident

SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"

RESOLVED INVALID SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported an OCSP status-reporting issue affecting its precertificates. The problem was discovered during SSL.com’s investigation after reviewing OCSP issues encountered by other CAs (including Let's Encrypt and GlobalSign), and SSL.com found precertificates that did not have corresponding issued certificates and that returned an OCSP status of "Unknown". SSL.com stated that its research indicated the issue was related to EJBCA and opened a ticket with PrimeKey to address the EJBCA problem. SSL.com reported that, after PrimeKey feedback, it imported all affected certificates into its database and its OCSP server no longer returned "Unknown" for the affected items. SSL.com also stated that it applied in-house remediation to resolve remaining issues and that it intended to publish a full incident report in the bug once investigation was complete. A Mozilla participant later resolved the incident as INVALID, referencing a discussion on the mozilla.dev.security.policy mailing list.

Model: gpt-5.4-nano Generated: 2026-06-13 19:35 UTC Revised: 2026-06-16 18:38 UTC Confidence: 0.90 6 comments
Chronology
  1. SSL.com discovered and confirmed an OCSP issue where precertificates without corresponding issued certificates returned an OCSP status of "Unknown".
  2. SSL.com received feedback from PrimeKey and updated its OCSP handling so the OCSP server no longer returned "Unknown" for affected certificates.
  3. SSL.com continued consultation with PrimeKey and applied further remediation after testing showed not all items returned the expected OCSP status.
  4. SSL.com applied in-house remediation to resolve remaining issues.
  5. Mozilla resolved the incident as INVALID following discussion on mozilla.dev.security.policy.
Thread Activity
  1. SSL.com — SSL.com reported that its investigation found precertificates without corresponding issued certificates that returned OCSP status "Unknown" and said it would remediate after PrimeKey provides a fix.
  2. Community commenter — Ryan asked whether the bug was meant to be the full incident report or whether SSL.com planned further updates, and requested a timeline if more details would be provided.
  3. SSL.com — SSL.com said it wanted to inform the community early, planned to follow Mozilla best practices, and would submit a preliminary report soon while waiting for PrimeKey feedback.
  4. SSL.com — SSL.com stated its research was ongoing and that a full report would be published when the investigation was complete.
  5. SSL.com — SSL.com posted a detailed incident report including how it discovered the issue, the actions taken, and links to crt.sh results for the affected precertificates.
  6. Fastly representative — Wthayer thanked SSL.com for the incident report and resolved the incident as INVALID, citing the outcome of discussion on mozilla.dev.security.policy.
Participants
SSL.com Community commenter Fastly representative
Similar Local Cases
#1722089 RESOLVED Incident Opened 2021-07-23 · Closed 2023-02-22 · 95% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 89% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1927532 RESOLVED Incident Opened 2024-10-28 · Closed 2025-08-26 · 89% similar
SSL.com: Issuance of certificates using keys previously reported as compromised
#1931636 RESOLVED Incident Opened 2024-11-15 · Closed 2025-02-12 · 88% similar
SSL.com: Delay in publishing OCSP responses
#1938236 RESOLVED Incident Revocation Issue Opened 2024-12-18 · Closed 2025-02-28 · 87% similar
SSL.com: Failure to process CAA records from one SubCA
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 86% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1563573 RESOLVED Incident Opened 2019-07-04 · Closed 2023-02-22 · 77% similar
DigiCert: Failure to disclose Unconstrained Intermediate within 7 Days
#1575125 RESOLVED Incident Opened 2019-08-20 · Closed 2024-06-30 · 76% similar
DigiCert: Apple: Unconstrained intermediate CAs not included in WTBR report

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action