← SSL.com cases
Bugzilla #1800753 Certificate Problem Report

SSL.com: Delayed revocation of certificate with weak key

RESOLVED WONTFIX SSL.com
AI Summary

SSL.com faced a compliance issue regarding the delayed revocation of a certificate containing keys vulnerable to Fermat factorization. The certificate was revoked 25 hours and 50 minutes after the CA was made aware of the vulnerability, exceeding the required 24-hour revocation timeline. SSL.com acknowledged the issue and explained their decision-making process, which involved analyzing the vulnerability and determining the appropriate course of action. The case raised discussions about the clarity of the Baseline Requirements regarding weak keys and the need for better guidance for CAs.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Confidence: 0.90
Chronology
  1. Vulnerability information shared on mailing list.
  2. CA publicly confirmed awareness of the certificate.
  3. Certificate revoked.
  4. Case closed.
Participants
Matthias secauditor@ssl.com bwilson@mozilla.com aaron@letsencrypt.org
Similar Local Cases
#1722089 RESOLVED Certificate Problem Report Opened 2021-07-23 · Closed 2023-02-22 · 65% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1666872 RESOLVED Certificate Problem Report Opened 2020-09-23 · Closed 2023-02-22 · 64% similar
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate
#1790693 RESOLVED Certificate Problem Report Opened 2022-09-13 · Closed 2023-03-24 · 64% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1938236 RESOLVED Certificate Problem Report Opened 2024-12-18 · Closed 2025-02-28 · 64% similar
SSL.com: Failure to process CAA records from one SubCA
#1719916 RESOLVED Certificate Problem Report Opened 2021-07-09 · Closed 2023-02-22 · 63% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1932973 RESOLVED Certificate Problem Report Opened 2024-11-22 · Closed 2025-04-07 · 63% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1942270 RESOLVED Certificate Problem Report Opened 2025-01-17 · Closed 2025-04-07 · 58% similar
SSL.com: Revocation process requires submission to a form that is unusable
#2029230 RESOLVED Certificate Problem Report Opened 2026-04-03 · Closed 2026-05-28 · 56% similar
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action