← SSL.com cases
Bugzilla #1722089 Incident

SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported a compliance failure involving the issuance of three Extended Validation (EV) TLS certificates without the required two-person validation. The issue was discovered by their validation team during a routine check. Upon investigation, it was found that a bug in their API allowed certificates to be issued without proper approval. SSL.com promptly revoked the affected certificates and implemented a hotfix to prevent further occurrences. They have since conducted a thorough review of their processes and are updating their documentation and training to enhance compliance and prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:02 UTC Revised: 2026-06-16 18:42 UTC Confidence: 0.90 20 comments
Chronology
  1. All three affected certificates revoked.
Thread Activity
  1. SSL.com — Filed initial Bugzilla report.
  2. SSL.com — This is our final report on this issue.
  3. Mozilla representative — It appears that the remediation items have been completed.
Participants
SSL.com Community commenter Mozilla representative
External References
Similar Local Cases
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 98% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1938236 RESOLVED Incident Revocation Issue Opened 2024-12-18 · Closed 2025-02-28 · 98% similar
SSL.com: Failure to process CAA records from one SubCA
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 97% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1931636 RESOLVED Incident Opened 2024-11-15 · Closed 2025-02-12 · 96% similar
SSL.com: Delay in publishing OCSP responses
#1579509 RESOLVED Incident Opened 2019-09-06 · Closed 2022-11-14 · 95% similar
SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"
#1927532 RESOLVED Incident Opened 2024-10-28 · Closed 2025-08-26 · 87% similar
SSL.com: Issuance of certificates using keys previously reported as compromised
#1705832 RESOLVED Incident Self Reported Incident Opened 2021-04-16 · Closed 2023-02-22 · 79% similar
KIR S.A.: DV certificates with locality name, organization name and stateOrProvinceName
#1753287 RESOLVED Incident Opened 2022-02-02 · Closed 2024-07-08 · 79% similar
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action