SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
SSL.com reported a compliance failure involving the issuance of three Extended Validation (EV) TLS certificates without the required two-person validation. The issue was discovered by their validation team during a routine check. Upon investigation, it was found that a bug in their API allowed certificates to be issued without proper approval. SSL.com promptly revoked the affected certificates and implemented a hotfix to prevent further occurrences. They have since conducted a thorough review of their processes and are updating their documentation and training to enhance compliance and prevent similar issues in the future.
- All three affected certificates revoked.
- SSL.com — Filed initial Bugzilla report.
- SSL.com — This is our final report on this issue.
- Mozilla representative — It appears that the remediation items have been completed.