SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate
SSL.com reported that, during its annual WebTrust audit, external auditors found that validation evidence for the localityName attribute of a single OV SSL certificate was not satisfactorarily retained. SSL.com stated that the issue was initially raised by the external auditors on 2020-08-18 and that SSL.com later declared it an incident under its Incident Management Policy and filed this Bugzilla report on 2020-09-23. SSL.com said it revoked the affected certificate within the required time frame and performed remediation after analysis, including introducing a new simplified step-by-step validation panel that prevents finalizing validation until requirements are specifically verified and mapped to retained evidence. SSL.com also reported completing an investigation of the entire OV corpus and determining that the affected certificate was the only impacted item, with no issues found in other certificates. SSL.com stated that the remediation was reviewed and approved by its internal compliance team and demonstrated to its external auditors. The bug is marked RESOLVED with resolution FIXED, and Mozilla indicated it would close the bug on or about 30-October-2020 unless additional unresolved issues remained to discuss.
- External auditors reported a localityName evidence retention issue for a single OV SSL certificate during SSL.com’s annual WebTrust audit.
- SSL.com revoked the affected OV certificate and began incident investigation and remediation work under its Incident Management Policy.
- SSL.com applied the remediation solution in production and demonstrated it to external auditors.
- SSL.com declared the finding an incident and filed this Bugzilla report after final assessment with external auditors.
- SSL.com filed the full incident report after completing in-depth review of the potentially impacted certificate corpus.
- SSL.com — Reported that annual audit testing found localityName validation evidence was not satisfactorily retained for one OV certificate, described incident handling, revocation, and remediation via a new validation panel, and stated the full incident report would follow.
- SSL.com — Provided a detailed timeline explaining how SSL.com became aware of the issue, how it was classified as an incident, what actions were taken (including revocation and remediation), and stated that only the single certificate was impacted.
- Mozilla representative — Indicated Mozilla would close the bug on or about 30-October-2020 unless additional unresolved issues remained.