SSL.com: Intermediate certificate not listed in audit reports
SSL.com reported an ALV (audit/ALV flag) issue in CCADB indicating that a certificate was not properly covered in audit reporting. SSL.com said it first became aware of the issue by observing the ALV flag in CCADB, initially assuming it was related to another audit-reporting bug, and then later determining the underlying problem stemmed from an unsubmitted root certificate. SSL.com consulted Mozilla’s MRSP for guidance and discussed options with external auditors, ultimately filing this incident bug. SSL.com stated that the problematic certificate was a root CA certificate that was not introduced as a Trust Anchor to Mozilla and was not in use, and that the issue involved one root CA certificate issued April 6, 2017. SSL.com reported that the audit case referenced in the thread (00000564) was completed and that this case resolves the ALV issue described above. A Fastly participant confirmed the issue was resolved via the updated audit statement.
- SSL.com reviewed an ALV flag in CCADB and began investigating the underlying cause.
- SSL.com requested guidance from MRSP on how to address the ALV issue.
- SSL.com conferred with external auditors about resolution options.
- SSL.com filed this incident bug after receiving further MRSP guidance.
- SSL.com completed the referenced audit case to resolve the ALV issue.
- SSL.com — SSL.com explained how it discovered the ALV flag in CCADB, investigated the cause as an unsubmitted root, consulted MRSP and external auditors, and filed the incident bug.
- SSL.com — SSL.com stated that audit case 00000564 had been completed and that it resolves the ALV issue described in the bug.
- Fastly representative — Confirmed the issue is resolved via the updated audit statement.