← SSL.com cases
Bugzilla #1666872
Certificate Problem Report
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate
RESOLVED
FIXED
SSL.com
AI Summary
SSL.com identified an issue during their annual audit where the validation evidence for the localityName attribute of an OV SSL certificate was not adequately retained. This was discovered by external auditors and led to the revocation of the affected certificate. SSL.com implemented a new validation process to ensure all requirements are verified and documented. The issue was declared an incident, and a complete report was filed following thorough investigation and remediation actions.
Chronology
- Locality issue reported by external auditors.
- Issue declared an incident and Bugzilla report filed.
- Full report filed.
Participants
secauditor@ssl.com
bwilson@mozilla.com
External References
Similar Local Cases
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
SSL.com: Failure to process CAA records from one SubCA
SSL.com: Delayed revocation of certificate with weak key
SSL.com: CAA Empty set handling results in Wildcard issuance
SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service