← SSL.com cases
Bugzilla #1678720 Certificate Misissuance

SSL.com: Wildcard DV certificate issued with a non-validated domain name

RESOLVED FIXED SSL.com
AI Summary

SSL.com reported a misissuance of a wildcard DV certificate due to a typographical error in the domain name. The issue was identified by a validation specialist immediately after the certificate was issued, leading to its revocation within minutes. An internal investigation confirmed that the misissuance was a result of a rare combination of access privileges and manual actions. SSL.com has since implemented technical measures to prevent similar occurrences in the future, and a thorough review found no other similar cases.

Model: gpt-4o-mini Generated: 2026-06-13 21:02 UTC Confidence: 0.95
Chronology
  1. Certificate mis-issuance identified and revoked
  2. Initial Bugzilla report filed
  3. Final Bugzilla report filed
Participants
secauditor@ssl.com bwilson@mozilla.com ryan.sleevi@gmail.com
External References
Similar Local Cases
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 77% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1750631 RESOLVED Certificate Misissuance Opened 2022-01-17 · Closed 2024-06-30 · 70% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1850171 RESOLVED Certificate Misissuance Opened 2023-08-25 · Closed 2023-09-29 · 68% similar
SSL.com: S/MIME certificates issued prior to validation
#1871113 RESOLVED Certificate Misissuance Opened 2023-12-20 · Closed 2024-05-15 · 67% similar
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN
#1711432 RESOLVED Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 58% similar
Telekom Security: Certificate with invalid FQDN
#1736064 RESOLVED Certificate Misissuance Opened 2021-10-15 · Closed 2023-02-22 · 58% similar
Sectigo: Subject field with unvalidated information included in certificates
#1674886 RESOLVED Certificate Misissuance Opened 2020-11-02 · Closed 2023-02-22 · 57% similar
certSIGN: misissued an OV SSL certificate with no organizationName and localityName, instead of a DV SSL as requested by client
#1662382 RESOLVED Certificate Misissuance Opened 2020-09-01 · Closed 2023-02-22 · 56% similar
GDCA: Incorrect Value in organizationName Field

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action