← SSL.com cases
Bugzilla #1724520 Certificate Misissuance

SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported an incident involving the issuance of a TLS certificate with a malformed common name due to a bug in their code. The issue was first identified on July 26, 2021, when a customer noticed the problem and revoked the certificate. SSL.com conducted an investigation, confirmed that the bug only affected one certificate, and deployed a hotfix within a day. They have since implemented a series of improvements to their validation procedures and software development lifecycle to prevent similar issues in the future. The case has been resolved with a final report filed on September 17, 2021.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:42 UTC Confidence: 0.85 16 comments
Chronology
  1. A TLS certificate was issued with a malformed common name.
  2. SSL.com filed a final report regarding the incident.
Thread Activity
  1. SSL.com — Filed initial Bugzilla report regarding the incident.
  2. SSL.com — Confirmed that a hotfix was deployed and no further similar issuances can occur.
  3. SSL.com — Filed final Bugzilla report detailing the incident and remediation actions.
Participants
SSL.com Community commenter Mozilla representative
External References
Similar Local Cases
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 100% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 99% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1850171 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-08-25 · Closed 2023-09-29 · 97% similar
SSL.com: S/MIME certificates issued prior to validation
#1961406 RESOLVED Certificate Misissuance Opened 2025-04-18 · Closed 2025-07-02 · 90% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1719916 RESOLVED Certificate Misissuance Opened 2021-07-09 · Closed 2023-02-22 · 85% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1718552 RESOLVED Certificate Misissuance Opened 2021-06-28 · Closed 2023-02-22 · 82% similar
IdenTrust: Certificates with Invalid values for stateOrProvinceName
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 80% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1636140 RESOLVED Certificate Misissuance Opened 2020-05-07 · Closed 2023-02-22 · 80% similar
SwissSign: duplicate serial number

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action