← SSL.com cases
Bugzilla #1678720 Certificate Misissuance

SSL.com: Wildcard DV certificate issued with a non-validated domain name

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported a preliminary incident in which a validation specialist found a DCV irregularity immediately after processing a wildcard DV server certificate request that contained a typographical mistake in the domain name. SSL.com stated that the issue resulted in certificate mis-issuance and that the problematic certificate was revoked immediately after issuance. SSL.com initiated an incident response: security auditors reviewed the issue, temporary measures were communicated to validation specialists to stop using the administrative tool that enabled the mis-issuance, and engineers reproduced the issue and began implementing technical remediation measures. SSL.com later confirmed that its investigation found no other occurrences, and security auditors completed review of the target population. Mozilla staff indicated the incident appeared appropriately remediated and planned to close the bug on or about 15-Jan-2021 unless additional questions arose. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:02 UTC Revised: 2026-06-16 18:40 UTC Confidence: 0.90 6 comments
Chronology
  1. SSL.com’s DCV system processed a wildcard DV request with a typographical domain mistake, resulting in certificate mis-issuance and immediate revocation.
  2. SSL.com escalated the issue to an incident and began implementing technical remediation measures after reproducing the problem.
  3. SSL.com completed review of the target certificate population and confirmed no other occurrences existed.
  4. Mozilla planned to close the bug after confirming remediation, barring further questions.
Thread Activity
  1. SSL.com — SSL.com opened the preliminary incident report, describing how a validation specialist found a DCV irregularity after processing a wildcard DV request with a typographical domain mistake and providing a detailed incident timeline including mis-issuance and revocation.
  2. SSL.com — SSL.com provided a progress update stating the investigation was ongoing to confirm no other occurrences and that technical measures had already been introduced.
  3. SSL.com — SSL.com updated that the investigation finished, confirmed no other occurrences, and that security auditors were reviewing a final report.
  4. SSL.com — SSL.com posted its final report, stating the investigation was completed and describing the incident timeline and remediation status.
  5. Mozilla representative — Mozilla indicated the incident/issue appeared appropriately remediated and that the bug would be closed on or about 15-Jan-2021 unless additional questions or issues arose.
  6. Community commenter — Acknowledged and thanked SSL.com for the detail in the final report.
Participants
SSL.com Mozilla representative Community commenter
External References
Similar Local Cases
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 100% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1850171 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-08-25 · Closed 2023-09-29 · 97% similar
SSL.com: S/MIME certificates issued prior to validation
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 96% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1961406 RESOLVED Certificate Misissuance Opened 2025-04-18 · Closed 2025-07-02 · 89% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1719916 RESOLVED Certificate Misissuance Opened 2021-07-09 · Closed 2023-02-22 · 85% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1534145 RESOLVED Certificate Misissuance Opened 2019-03-10 · Closed 2023-02-22 · 83% similar
SSL.com: P-384 curve / ecdsa-with-SHA256 certificates
#1651026 RESOLVED Certificate Misissuance Incident Remediation Tracking Opened 2020-07-07 · Closed 2023-02-22 · 79% similar
Izenpe: certificate issued to internal domain
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 78% similar
e-commerce monitoring GmbH: CN domain not in SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action