SSL.com: Wildcard DV certificate issued with a non-validated domain name
SSL.com reported a preliminary incident in which a validation specialist found a DCV irregularity immediately after processing a wildcard DV server certificate request that contained a typographical mistake in the domain name. SSL.com stated that the issue resulted in certificate mis-issuance and that the problematic certificate was revoked immediately after issuance. SSL.com initiated an incident response: security auditors reviewed the issue, temporary measures were communicated to validation specialists to stop using the administrative tool that enabled the mis-issuance, and engineers reproduced the issue and began implementing technical remediation measures. SSL.com later confirmed that its investigation found no other occurrences, and security auditors completed review of the target population. Mozilla staff indicated the incident appeared appropriately remediated and planned to close the bug on or about 15-Jan-2021 unless additional questions arose. The bug was resolved as FIXED.
- SSL.com’s DCV system processed a wildcard DV request with a typographical domain mistake, resulting in certificate mis-issuance and immediate revocation.
- SSL.com escalated the issue to an incident and began implementing technical remediation measures after reproducing the problem.
- SSL.com completed review of the target certificate population and confirmed no other occurrences existed.
- Mozilla planned to close the bug after confirming remediation, barring further questions.
- SSL.com — SSL.com opened the preliminary incident report, describing how a validation specialist found a DCV irregularity after processing a wildcard DV request with a typographical domain mistake and providing a detailed incident timeline including mis-issuance and revocation.
- SSL.com — SSL.com provided a progress update stating the investigation was ongoing to confirm no other occurrences and that technical measures had already been introduced.
- SSL.com — SSL.com updated that the investigation finished, confirmed no other occurrences, and that security auditors were reviewing a final report.
- SSL.com — SSL.com posted its final report, stating the investigation was completed and describing the incident timeline and remediation status.
- Mozilla representative — Mozilla indicated the incident/issue appeared appropriately remediated and that the bug would be closed on or about 15-Jan-2021 unless additional questions or issues arose.
- Community commenter — Acknowledged and thanked SSL.com for the detail in the final report.