SSL.com: Issuance of TLS certificates with prohibited DV validation methods (SC-45)
SSL.com reported an incident after its internal Quarterly Certificate Review on 2021-12-29 identified three DV TLS certificates that were issued using validation methods prohibited by SC-45. The issue triggered an investigation to discover the full population of affected certificates. SSL.com escalated the security event to an incident, deployed a hotfix to its RA system to prevent similar issuance, and conducted research across its TLS certificate corpus, identifying 706 potentially affected certificates. SSL.com revoked the affected active certificates; it reported that a technical issue caused 53 certificates to be missed during bulk revocation, and that revocation of those certificates occurred the next day, with all affected active certificates revoked by 2022-01-25. In its final report, SSL.com attributed the incident to delayed adoption of SC-45 changes after 2021-09-01 and insufficient implementation of the SC-45 update in its RA Portal, including that the RA Portal update addressed SC-45 related issuances but not re-issuances based on re-using validation evidence. SSL.com completed remediation actions including updating its Monitoring Policy and the related Procedure to monitor updates in external requirements, and conducting internal training for Trusted Roles and SDLC-related personnel. Mozilla closed the bug as complete.
- SSL.com’s Quarterly Certificate Review identified three DV TLS certificates issued with SC-45-prohibited validation methods, triggering an investigation.
- SSL.com escalated the security event to an incident and began expanded investigation of the affected issuance period.
- SSL.com deployed a hotfix to its RA system to prevent similar problematic issuance.
- SSL.com initiated and completed revocation of affected active certificates, with follow-up revocation for certificates missed due to a technical issue.
- Mozilla closed the bug as complete after SSL.com reported completion of remediation actions.
- SSL.com — Created a preliminary incident report attachment and stated that internal QCR identified three DV TLS certificates issued with validation methods prohibited by SC-45.
- SSL.com — Reported revocation progress, including that 53 certificates were not revoked during bulk revocation due to a technical issue and were revoked the next day; acknowledged a CP/CPS revocation-timeline violation and opened a separate bug for it.
- SSL.com — Reported that Bug 1752636 was opened to document the delayed revocation issue.
- SSL.com — Provided postmortem findings: delayed adoption of SC-45 changes after 2021-09-01 and insufficient implementation of the SC-45 update in the RA Portal.
- SSL.com — Expanded on contributing failures and described remediation measures, including updates to monitoring and SDLC processes and planned training.
- SSL.com — Submitted the final report describing the incident discovery, timeline, investigation, and contributing issues.
- SSL.com — Reported completion of remediation actions, including adoption of an updated Monitoring Policy and ERP procedure and completion of internal training.
- Mozilla representative — Closed the bug as complete.