← SSL.com cases
Bugzilla #1790693 Self Reported Incident Revocation Issue

SSL.com: Issuance of 1 EV TLS certificate using an Incorporating Agency not included in the approved list

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported a compliance issue discovered during its Q2 2022 internal Quarterly Certificate Review (QCR). The CA found that one EV TLS certificate was issued using an Incorporating Agency (IA) that was not disclosed in SSL.com’s List of Approved Incorporating and Registration Agencies at the time of issuance. SSL.com escalated the issue as an incident and notified customer-facing teams to proceed with revocation within the required 5-day time frame. SSL.com revoked the affected certificate on 2022-09-18. The CA also prepared and deployed an update to its Validation Control Panel to require Validation Specialists to use only approved and disclosed IA sources before issuing Extended Validation certificates. SSL.com completed analysis of the target population and reported that no other EV TLS certificates were impacted, and requested closure of the bug. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:44 UTC Confidence: 0.90 8 comments
Chronology
  1. SSL.com issued one EV TLS certificate using an Incorporating Agency that was not disclosed in its approved list at the time.
  2. SSL.com revoked the affected certificate following incident handling.
  3. SSL.com deployed a Validation Control Panel update enforcing use of only approved and disclosed IA sources.
  4. Mozilla closed the bug as resolved (FIXED).
Thread Activity
  1. SSL.com — SSL.com filed a preliminary incident report stating that Q2 2022 QCR discovered one EV TLS certificate issued with an IA not on its Approved List at issuance time.
  2. Mozilla representative — Mozilla acknowledged the report and asked for an update.
  3. SSL.com — SSL.com reported revocation of the affected certificate on 2022-09-18 and progress on a Validation Control Panel update to enforce approved IA sources.
  4. SSL.com — SSL.com reported the Validation Control Panel update had been deployed to production, adding a required step for approved IA sources before EV issuance.
  5. SSL.com — SSL.com reported completion of analysis of the target population and expected to file the full incident report by the end of the following week.
  6. SSL.com — SSL.com stated its investigation concluded and delivered the final incident report.
  7. SSL.com — With no further comments, SSL.com requested closure of the bug.
  8. Mozilla representative — Mozilla stated it would close the bug on or about 2023-03-24 unless there were additional questions.
Participants
SSL.com Mozilla representative
Similar Local Cases
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 98% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#2029230 RESOLVED Self Reported Incident Revocation Issue Opened 2026-04-03 · Closed 2026-05-28 · 98% similar
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#1938236 RESOLVED Incident Revocation Issue Opened 2024-12-18 · Closed 2025-02-28 · 96% similar
SSL.com: Failure to process CAA records from one SubCA
#1962809 RESOLVED Self Reported Incident Revocation Issue Opened 2025-04-25 · Closed 2025-07-28 · 96% similar
SSL.com: Expired certificate for a “Valid” Test Website
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 89% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#1718771 RESOLVED Self Reported Incident Revocation Issue Opened 2021-06-30 · Closed 2023-02-22 · 79% similar
Sectigo: DCV Reuse after 825 days
#1794047 RESOLVED Revocation Issue Self Reported Incident Opened 2022-10-06 · Closed 2023-02-22 · 79% similar
IdenTrust: Missing Revocation Reasons in CRL
#1649951 RESOLVED Self Reported Incident Revocation Issue Opened 2020-07-02 · Closed 2023-02-22 · 78% similar
DigiCert: Incorrect OCSP Delegated Responder Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action