← SSL.com cases
Bugzilla #1620772 Security Incident

SSL.com: Issued precertificate with Debian Weak Key

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves SSL.com issuing a precertificate that contained a known weak key associated with Debian. The issue was reported by a user on the Mozilla security policy mailing list, prompting SSL.com to initiate an investigation. SSL.com confirmed the issuance of the certificate and revoked it within 24 hours, as per their compliance policies. They also updated their weak key blacklist and implemented additional checks to prevent future occurrences. The case has been resolved with SSL.com committing to ongoing improvements in their processes.

Model: gpt-4o-mini Generated: 2026-06-13 21:02 UTC Revised: 2026-06-16 18:39 UTC Confidence: 0.85 20 comments
Chronology
  1. SSL.com received a Certificate Problem Report regarding a precertificate with a weak Debian key.
  2. SSL.com completed testing of a new weak key detection engine and pushed it to production.
  3. The case was discussed regarding the effectiveness of SSL.com's remediation efforts.
Thread Activity
  1. Community commenter — Reported the issuance of a precertificate with a known weak key.
  2. SSL.com — Confirmed receipt of the report and initiated an investigation.
  3. SSL.com — Provided an update on the investigation and actions taken.
  4. Fastly representative — Noted that all questions have been answered and remediation is complete.
Participants
Community commenter SSL.com Fastly representative
External References
Similar Local Cases
#1427034 RESOLVED Ca Security Vulnerability Security Incident Opened 2017-12-25 · Closed 2024-05-09 · 68% similar
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
#543881 VERIFIED Externally Reported Incident Security Incident Audit Finding Opened 2010-02-03 · Closed 2022-11-14 · 57% similar
please remove Wells Fargo from your listing of root CA's
#1554259 RESOLVED Self Reported Incident Security Incident Opened 2019-05-24 · Closed 2023-02-22 · 56% similar
GlobalSign: SPKI lacks explicit NULL parameter,
#1577014 RESOLVED Security Incident Opened 2019-08-27 · Closed 2023-02-22 · 55% similar
DigiCert: OCSP services returns 1 byte
#1484766 RESOLVED Self Reported Incident Revocation Issue Security Incident Opened 2018-08-20 · Closed 2024-06-30 · 55% similar
GoDaddy: Random Value Vulnerability in Domain Validation Method
#1942270 RESOLVED Revocation Issue Repository Issue Opened 2025-01-17 · Closed 2025-04-07 · 52% similar
SSL.com: Revocation process requires submission to a form that is unusable
#1579509 RESOLVED Incident Opened 2019-09-06 · Closed 2022-11-14 · 48% similar
SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 46% similar
DigiCert: OCSP responder returning invalid responses

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action