← SSL.com cases
Bugzilla #1722089 Certificate Problem Report

SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information

RESOLVED FIXED SSL.com
AI Summary

SSL.com issued three Extended Validation (EV) TLS certificates without the required two-person validation process. The issue was identified during a routine check by their validation team, leading to an internal investigation. A bug in their API was discovered, which allowed certificates to be issued without proper validation evidence. All three affected certificates were revoked promptly after the issue was confirmed. SSL.com has since implemented a hotfix and is reviewing their processes to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:02 UTC Confidence: 1.00
Chronology
  1. EV TLS order reviewed and approved by a Validation Specialist.
  2. Customer care requests an update on the order.
  3. Issue reported after discovering lack of 2p approval evidence.
  4. All three affected certificates revoked.
  5. Final Bugzilla report filed.
Participants
secauditor@ssl.com ryan.sleevi@gmail.com bwilson@mozilla.com mathew.hodson@gmail.com
External References
Similar Local Cases
#1719916 RESOLVED Certificate Problem Report Opened 2021-07-09 · Closed 2023-02-22 · 75% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1790693 RESOLVED Certificate Problem Report Opened 2022-09-13 · Closed 2023-03-24 · 70% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1938236 RESOLVED Certificate Problem Report Opened 2024-12-18 · Closed 2025-02-28 · 69% similar
SSL.com: Failure to process CAA records from one SubCA
#1666872 RESOLVED Certificate Problem Report Opened 2020-09-23 · Closed 2023-02-22 · 68% similar
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate
#1579509 RESOLVED Certificate Problem Report Opened 2019-09-06 · Closed 2022-11-14 · 66% similar
SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"
#1932973 RESOLVED Certificate Problem Report Opened 2024-11-22 · Closed 2025-04-07 · 66% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1800753 RESOLVED Certificate Problem Report Opened 2022-11-15 · Closed 2023-07-21 · 65% similar
SSL.com: Delayed revocation of certificate with weak key
#1961406 RESOLVED Certificate Problem Report Opened 2025-04-18 · Closed 2025-07-02 · 61% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action