SSL.com: Issuance of 1 EV TLS certificate using an Incorporating Agency not included in the approved list
SSL.com reported a compliance issue discovered during its Q2 2022 internal Quarterly Certificate Review (QCR). The CA found that one EV TLS certificate was issued using an Incorporating Agency (IA) that was not disclosed in SSL.com’s List of Approved Incorporating and Registration Agencies at the time of issuance. SSL.com escalated the issue as an incident and notified customer-facing teams to proceed with revocation within the required 5-day time frame. SSL.com revoked the affected certificate on 2022-09-18. The CA also prepared and deployed an update to its Validation Control Panel to require Validation Specialists to use only approved and disclosed IA sources before issuing Extended Validation certificates. SSL.com completed analysis of the target population and reported that no other EV TLS certificates were impacted, and requested closure of the bug. The bug was resolved as FIXED.
- SSL.com issued one EV TLS certificate using an Incorporating Agency that was not disclosed in its approved list at the time.
- SSL.com revoked the affected certificate following incident handling.
- SSL.com deployed a Validation Control Panel update enforcing use of only approved and disclosed IA sources.
- Mozilla closed the bug as resolved (FIXED).
- SSL.com — SSL.com filed a preliminary incident report stating that Q2 2022 QCR discovered one EV TLS certificate issued with an IA not on its Approved List at issuance time.
- Mozilla representative — Mozilla acknowledged the report and asked for an update.
- SSL.com — SSL.com reported revocation of the affected certificate on 2022-09-18 and progress on a Validation Control Panel update to enforce approved IA sources.
- SSL.com — SSL.com reported the Validation Control Panel update had been deployed to production, adding a required step for approved IA sources before EV issuance.
- SSL.com — SSL.com reported completion of analysis of the target population and expected to file the full incident report by the end of the following week.
- SSL.com — SSL.com stated its investigation concluded and delivered the final incident report.
- SSL.com — With no further comments, SSL.com requested closure of the bug.
- Mozilla representative — Mozilla stated it would close the bug on or about 2023-03-24 unless there were additional questions.