← SSL.com cases
Bugzilla #1610000 Audit Finding

SSL.com: Intermediate certificate not listed in audit reports

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported an ALV (audit/ALV flag) issue in CCADB indicating that a certificate was not properly covered in audit reporting. SSL.com said it first became aware of the issue by observing the ALV flag in CCADB, initially assuming it was related to another audit-reporting bug, and then later determining the underlying problem stemmed from an unsubmitted root certificate. SSL.com consulted Mozilla’s MRSP for guidance and discussed options with external auditors, ultimately filing this incident bug. SSL.com stated that the problematic certificate was a root CA certificate that was not introduced as a Trust Anchor to Mozilla and was not in use, and that the issue involved one root CA certificate issued April 6, 2017. SSL.com reported that the audit case referenced in the thread (00000564) was completed and that this case resolves the ALV issue described above. A Fastly participant confirmed the issue was resolved via the updated audit statement.

Model: gpt-5.4-nano Generated: 2026-06-13 21:02 UTC Revised: 2026-06-16 18:39 UTC Confidence: 0.86 3 comments
Chronology
  1. SSL.com reviewed an ALV flag in CCADB and began investigating the underlying cause.
  2. SSL.com requested guidance from MRSP on how to address the ALV issue.
  3. SSL.com conferred with external auditors about resolution options.
  4. SSL.com filed this incident bug after receiving further MRSP guidance.
  5. SSL.com completed the referenced audit case to resolve the ALV issue.
Thread Activity
  1. SSL.com — SSL.com explained how it discovered the ALV flag in CCADB, investigated the cause as an unsubmitted root, consulted MRSP and external auditors, and filed the incident bug.
  2. SSL.com — SSL.com stated that audit case 00000564 had been completed and that it resolves the ALV issue described in the bug.
  3. Fastly representative — Confirmed the issue is resolved via the updated audit statement.
Participants
SSL.com Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1867851 RESOLVED Ca Documents Audit Finding Opened 2023-12-01 · Closed 2024-04-24 · 87% similar
SSL.com: Findings in 2023 audit
#1588213 RESOLVED Ca Documents Audit Finding Opened 2019-10-11 · Closed 2024-06-30 · 68% similar
IdenTrust: Missing Thumbprints for Intermediate CA certificates In Some Annual Audit Reports
#1549862 RESOLVED Ca Documents Audit Finding Opened 2019-05-07 · Closed 2023-02-22 · 68% similar
Entrust: Outdated audit statement for intermediate cert
#1581597 RESOLVED Ca Documents Audit Finding Opened 2019-09-16 · Closed 2023-02-22 · 66% similar
QuoVadis: Unconstrained CAs missing audits
#1412950 RESOLVED Ca Documents Audit Finding Opened 2017-10-30 · Closed 2024-06-30 · 66% similar
Firmaprofesional: Insufficient Audit Statements
#1614444 RESOLVED Ca Certificate Compliance Audit Finding Opened 2020-02-10 · Closed 2024-06-30 · 60% similar
Chunghwa Telecom: ALV failures on intermediate certificates
#1897134 RESOLVED Audit Finding Opened 2024-05-16 · Closed 2024-09-06 · 60% similar
certSIGN: Findings in 2024 ETSI Audit - Audit Incident Report
#1614821 RESOLVED Audit Finding Opened 2020-02-11 · Closed 2024-06-30 · 60% similar
Dhimyotis / Certigna: Intermediate CAs missing audits

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action