← SSL.com cases
Bugzilla #1719916 Certificate Misissuance

SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns SSL.com’s issuance of an EV TLS certificate where the certificate’s “O” (organization) field value was incorrect. SSL.com stated that the issue was reported by a third party to SSL.com Support via email and then to SSL.com Security Auditors via an internal ticket. SSL.com investigated and confirmed the problem, and decided on immediate actions including reissuing the certificate with the correct “O” field value, contacting the customer regarding revocation, and revoking the affected certificate before 2021-07-08T17:00+00:00. SSL.com reported that the affected certificate was revoked on 2021-07-08T17:01:42 and that the customer initiated certificate replacement. SSL.com also conducted a review of its target population of potentially impacted EV and OV TLS certificates and reported finding one similar case, then later reported no other similar cases. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:02 UTC Revised: 2026-06-16 18:41 UTC Confidence: 0.86 10 comments
Chronology
  1. SSL.com issued an EV TLS certificate with serial number 10975D2ED70F692430714C4586E8BD78 to ansonnet.com.
  2. SSL.com received a third-party report of possible mis-issuance for the affected certificate and initiated an investigation.
  3. SSL.com revoked the affected certificate after confirming the issue.
  4. SSL.com completed its manual and cross-checked review of the target population and reported no other similar cases.
Thread Activity
  1. SSL.com — Filed a preliminary incident report describing how the issue was reported, providing a timeline, and stating that the investigation was ongoing.
  2. SSL.com — Reported progress reviewing 35% of the target population and stated the investigation was ongoing.
  3. SSL.com — Reported completion of review of the target population so far and discovered one similar case, listing impacted certificate serial numbers and crt.sh links.
  4. SSL.com — Reported completion of review of the target population and found no other similar cases, while stating the review was ongoing and would be extended to identify other discrepancies.
  5. SSL.com — Explained that the incorrect “O” value was submitted by the customer in the CSR and that SSL.com performed a manual and cross-checked review of 100% of potentially impacted certificates.
  6. SSL.com — Posted the final report on the issue, including the incident timeline and details of the target population review.
  7. Mozilla representative — Indicated the bug would be closed if there were no further questions or items to address.
Participants
SSL.com Community commenter Mozilla representative
Similar Local Cases
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 85% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 85% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 79% similar
QuoVadis: Incorrect keyUsage for ECC certificate
#1727963 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-08-28 · Closed 2023-02-22 · 78% similar
DigiCert: Truncation of Registration Number
#1667430 RESOLVED Certificate Misissuance Opened 2020-09-25 · Closed 2023-02-22 · 77% similar
Camerfirma: Invalid stateOrProvinceName field
#1759854 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-16 · Closed 2023-02-22 · 77% similar
GlobalSign: Certificate issued to FQDN with malformed CAA
#1760311 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-18 · Closed 2023-02-22 · 77% similar
GlobalSign: OCSP responder certificates with more than 64 characters in CN
#1653504 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-07-17 · Closed 2023-02-22 · 77% similar
Sectigo: Certificates with RSA keys where modulus is not divisible by 8

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action