← SSL.com cases
Bugzilla #1620772
Security Incident
SSL.com: Issued precertificate with Debian Weak Key
RESOLVED
FIXED
SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves SSL.com issuing a precertificate that contained a known weak key associated with Debian. The issue was reported by a user on the Mozilla security policy mailing list, prompting SSL.com to initiate an investigation. SSL.com confirmed the issuance of the certificate and revoked it within 24 hours, as per their compliance policies. They also updated their weak key blacklist and implemented additional checks to prevent future occurrences. The case has been resolved with SSL.com committing to ongoing improvements in their processes.
Chronology
- SSL.com received a Certificate Problem Report regarding a precertificate with a weak Debian key.
- SSL.com completed testing of a new weak key detection engine and pushed it to production.
- The case was discussed regarding the effectiveness of SSL.com's remediation efforts.
Thread Activity
- Community commenter — Reported the issuance of a precertificate with a known weak key.
- SSL.com — Confirmed receipt of the report and initiated an investigation.
- SSL.com — Provided an update on the investigation and actions taken.
- Fastly representative — Noted that all questions have been answered and remediation is complete.
Participants
Community commenter
SSL.com
Fastly representative
External References
Similar Local Cases
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
please remove Wells Fargo from your listing of root CA's
GlobalSign: SPKI lacks explicit NULL parameter,
DigiCert: OCSP services returns 1 byte
GoDaddy: Random Value Vulnerability in Domain Validation Method
SSL.com: Revocation process requires submission to a form that is unusable
SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"
DigiCert: OCSP responder returning invalid responses