← SSL.com cases
Bugzilla #1750631 Certificate Misissuance

SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45

RESOLVED FIXED SSL.com
AI Summary

SSL.com identified the issuance of three DV TLS certificates using validation methods prohibited by SC-45 during an internal review. The issue was discovered on December 29, 2021, leading to an investigation that confirmed the mis-issuance of these certificates. SSL.com took immediate action to revoke the affected certificates and implemented a hotfix to prevent similar future occurrences. The incident highlighted failures in the timely adoption of policy changes and insufficient implementation in their RA Portal. All remediation actions have since been completed, and the case has been resolved.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Confidence: 0.95
Chronology
  1. Discovery of three problematic certificates during internal review.
  2. Revocation of the affected certificates completed.
  3. All remediation actions completed and monitoring policy updated.
Participants
secauditor@ssl.com bwilson@mozilla.com
External References
Similar Local Cases
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 70% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 69% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1850171 RESOLVED Certificate Misissuance Opened 2023-08-25 · Closed 2023-09-29 · 69% similar
SSL.com: S/MIME certificates issued prior to validation
#1871113 RESOLVED Certificate Misissuance Opened 2023-12-20 · Closed 2024-05-15 · 66% similar
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN
#1736064 RESOLVED Certificate Misissuance Opened 2021-10-15 · Closed 2023-02-22 · 53% similar
Sectigo: Subject field with unvalidated information included in certificates
#1534145 RESOLVED Certificate Misissuance Opened 2019-03-10 · Closed 2023-02-22 · 53% similar
SSL.com: P-384 curve / ecdsa-with-SHA256 certificates
#1711432 RESOLVED Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 50% similar
Telekom Security: Certificate with invalid FQDN
#1696872 RESOLVED Certificate Misissuance Opened 2021-03-08 · Closed 2025-03-20 · 50% similar
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action