← SSL.com cases
Bugzilla #1666872 Validation Issue

SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported that, during its annual WebTrust audit, external auditors found that validation evidence for the localityName attribute of a single OV SSL certificate was not satisfactorarily retained. SSL.com stated that the issue was initially raised by the external auditors on 2020-08-18 and that SSL.com later declared it an incident under its Incident Management Policy and filed this Bugzilla report on 2020-09-23. SSL.com said it revoked the affected certificate within the required time frame and performed remediation after analysis, including introducing a new simplified step-by-step validation panel that prevents finalizing validation until requirements are specifically verified and mapped to retained evidence. SSL.com also reported completing an investigation of the entire OV corpus and determining that the affected certificate was the only impacted item, with no issues found in other certificates. SSL.com stated that the remediation was reviewed and approved by its internal compliance team and demonstrated to its external auditors. The bug is marked RESOLVED with resolution FIXED, and Mozilla indicated it would close the bug on or about 30-October-2020 unless additional unresolved issues remained to discuss.

Model: gpt-5.4-nano Generated: 2026-06-13 21:02 UTC Revised: 2026-06-16 18:40 UTC Confidence: 0.84 3 comments
Chronology
  1. External auditors reported a localityName evidence retention issue for a single OV SSL certificate during SSL.com’s annual WebTrust audit.
  2. SSL.com revoked the affected OV certificate and began incident investigation and remediation work under its Incident Management Policy.
  3. SSL.com applied the remediation solution in production and demonstrated it to external auditors.
  4. SSL.com declared the finding an incident and filed this Bugzilla report after final assessment with external auditors.
  5. SSL.com filed the full incident report after completing in-depth review of the potentially impacted certificate corpus.
Thread Activity
  1. SSL.com — Reported that annual audit testing found localityName validation evidence was not satisfactorily retained for one OV certificate, described incident handling, revocation, and remediation via a new validation panel, and stated the full incident report would follow.
  2. SSL.com — Provided a detailed timeline explaining how SSL.com became aware of the issue, how it was classified as an incident, what actions were taken (including revocation and remediation), and stated that only the single certificate was impacted.
  3. Mozilla representative — Indicated Mozilla would close the bug on or about 30-October-2020 unless additional unresolved issues remained.
Participants
SSL.com Mozilla representative
External References
Similar Local Cases
#1944815 RESOLVED Self Reported Incident Validation Issue Opened 2025-01-30 · Closed 2026-06-10 · 68% similar
GlobalSign: Organization-validated SMIME certificate with invalid organizationIdentifier for European country
#1575880 RESOLVED Self Reported Incident Revocation Issue Validation Issue Opened 2019-08-22 · Closed 2023-02-22 · 68% similar
GlobalSign: SSL Certificates with US country code and invalid State/Prov
#1917459 RESOLVED Validation Issue Opened 2024-09-08 · Closed 2025-02-14 · 68% similar
eMudhra emSign PKI Services : OCSP Responder Time Inconsistency
#1693304 RESOLVED Validation Issue Opened 2021-02-17 · Closed 2023-02-22 · 66% similar
FNMT: Issuance of QCP-n certificates without verifying identity
#1876593 RESOLVED Validation Issue Revocation Issue Opened 2024-01-25 · Closed 2024-06-06 · 66% similar
Google Trust Services: Failure to properly validate IP address
#1637093 RESOLVED Validation Issue Opened 2020-05-11 · Closed 2023-02-22 · 65% similar
Multicert: AIA CA Issuer field pointing to PEM encoded cert
#1790693 RESOLVED Self Reported Incident Revocation Issue Opened 2022-09-13 · Closed 2023-03-24 · 64% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 63% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action