← SSL.com cases
Bugzilla #1724520 Certificate Misissuance

SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels

RESOLVED FIXED SSL.com
AI Summary

SSL.com reported a misissuance incident involving a TLS certificate issued with a malformed common name due to a bug in their validation process. The issue arose when a customer demonstrated control over a domain but submitted a request that included a 'www.' string incorrectly positioned within the domain labels. This led to the issuance of a certificate that did not meet validation standards. SSL.com promptly revoked the certificate upon notification and implemented a hotfix to prevent similar occurrences. The investigation confirmed that this was the only affected certificate.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Confidence: 0.95
Chronology
  1. Customer reported malformed certificate issuance.
  2. Initial Bugzilla report filed.
  3. Final Bugzilla report filed.
Participants
secauditor@ssl.com ryan.sleevi@gmail.com mathew.hodson@gmail.com bwilson@mozilla.com
External References
Similar Local Cases
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 77% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1871113 RESOLVED Certificate Misissuance Opened 2023-12-20 · Closed 2024-05-15 · 74% similar
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN
#1750631 RESOLVED Certificate Misissuance Opened 2022-01-17 · Closed 2024-06-30 · 69% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1850171 RESOLVED Certificate Misissuance Opened 2023-08-25 · Closed 2023-09-29 · 69% similar
SSL.com: S/MIME certificates issued prior to validation
#1662382 RESOLVED Certificate Misissuance Opened 2020-09-01 · Closed 2023-02-22 · 57% similar
GDCA: Incorrect Value in organizationName Field
#1895006 RESOLVED Certificate Misissuance Opened 2024-05-03 · Closed 2024-08-23 · 56% similar
IdenTrust: unintended creation of a Root CA certificate
#1674886 RESOLVED Certificate Misissuance Opened 2020-11-02 · Closed 2023-02-22 · 56% similar
certSIGN: misissued an OV SSL certificate with no organizationName and localityName, instead of a DV SSL as requested by client
#1711432 RESOLVED Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 56% similar
Telekom Security: Certificate with invalid FQDN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action