← SSL.com cases
Bugzilla #1724520
Certificate Misissuance
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
RESOLVED
FIXED
SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
SSL.com reported an incident involving the issuance of a TLS certificate with a malformed common name due to a bug in their code. The issue was first identified on July 26, 2021, when a customer noticed the problem and revoked the certificate. SSL.com conducted an investigation, confirmed that the bug only affected one certificate, and deployed a hotfix within a day. They have since implemented a series of improvements to their validation procedures and software development lifecycle to prevent similar issues in the future. The case has been resolved with a final report filed on September 17, 2021.
Chronology
- A TLS certificate was issued with a malformed common name.
- SSL.com filed a final report regarding the incident.
Thread Activity
- SSL.com — Filed initial Bugzilla report regarding the incident.
- SSL.com — Confirmed that a hotfix was deployed and no further similar issuances can occur.
- SSL.com — Filed final Bugzilla report detailing the incident and remediation actions.
Participants
SSL.com
Community commenter
Mozilla representative
External References
Similar Local Cases
SSL.com: Wildcard DV certificate issued with a non-validated domain name
SSL.com: CAA Empty set handling results in Wildcard issuance
SSL.com: S/MIME certificates issued prior to validation
SSL.com: DCV bypass and issue fake certificates for any MX hostname
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
IdenTrust: Certificates with Invalid values for stateOrProvinceName
GlobalSign: Invalid stateOrProvinceName and locality pair
SwissSign: duplicate serial number