SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
This case concerns SSL.com’s issuance of an EV TLS certificate where the certificate’s “O” (organization) field value was incorrect. SSL.com stated that the issue was reported by a third party to SSL.com Support via email and then to SSL.com Security Auditors via an internal ticket. SSL.com investigated and confirmed the problem, and decided on immediate actions including reissuing the certificate with the correct “O” field value, contacting the customer regarding revocation, and revoking the affected certificate before 2021-07-08T17:00+00:00. SSL.com reported that the affected certificate was revoked on 2021-07-08T17:01:42 and that the customer initiated certificate replacement. SSL.com also conducted a review of its target population of potentially impacted EV and OV TLS certificates and reported finding one similar case, then later reported no other similar cases. The bug was resolved as FIXED.
- SSL.com issued an EV TLS certificate with serial number 10975D2ED70F692430714C4586E8BD78 to ansonnet.com.
- SSL.com received a third-party report of possible mis-issuance for the affected certificate and initiated an investigation.
- SSL.com revoked the affected certificate after confirming the issue.
- SSL.com completed its manual and cross-checked review of the target population and reported no other similar cases.
- SSL.com — Filed a preliminary incident report describing how the issue was reported, providing a timeline, and stating that the investigation was ongoing.
- SSL.com — Reported progress reviewing 35% of the target population and stated the investigation was ongoing.
- SSL.com — Reported completion of review of the target population so far and discovered one similar case, listing impacted certificate serial numbers and crt.sh links.
- SSL.com — Reported completion of review of the target population and found no other similar cases, while stating the review was ongoing and would be extended to identify other discrepancies.
- SSL.com — Explained that the incorrect “O” value was submitted by the customer in the CSR and that SSL.com performed a manual and cross-checked review of 100% of potentially impacted certificates.
- SSL.com — Posted the final report on the issue, including the incident timeline and details of the target population review.
- Mozilla representative — Indicated the bug would be closed if there were no further questions or items to address.