← SSL.com cases
Bugzilla #1832570 Ca Certificate Compliance Remediation Tracking Opened By Ca

SSL.com reseller/SubCA relationship and follow-up guidance after e-Tugra incident

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case was opened by Chris Clements to understand SSL.com’s relationship with e-Tugra after issues raised in Bug 1801345. SSL.com explained that e-Tugra was a reseller customer using hosted SubCA services, not a cross-signing partner, and that SSL.com retained control over key materials, validation, and issuance. SSL.com also clarified that reseller accounts could submit certificate orders and revocation requests, but domain validation and document verification were performed by SSL.com. In response to follow-up questions, SSL.com said it had no indication that e-Tugra generated private keys for subscribers, and it described the Certificate Services account as a username/email and password used to access the SSL.com certificate portal. SSL.com committed to create reseller guidance, revise agreement documents, and produce a white paper on lessons learned and good practices for branded SubCAs. The reseller guidance was published on 2023-10-12, and the white paper was later published on 2024-05-28. The bug was resolved FIXED.

Model: gpt-5.4-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.93 35 comments
Chronology
  1. Chris Clements opened a case about SSL.com’s reseller/SubCA handling in connection with issues from Bug 1801345.
  2. SSL.com stated that e-Tugra was a reseller customer using hosted SubCA services under SSL.com control.
  3. SSL.com said it had no indication that e-Tugra generated private keys for subscribers.
  4. SSL.com published its reseller security best-practices guide.
  5. SSL.com published the Lessons Learned White Paper for branded SubCAs.
  6. The bug was resolved FIXED.
Thread Activity
  1. Google representative — Chris Clements opened the report and asked how SSL.com ensures continued compliance for managed SubCAs and reseller systems in light of Bug 1801345.
  2. SSL.com — SSL.com explained that e-Tugra was a reseller customer, that SSL.com controlled the hosted SubCA, and that validation and issuance were not delegated to the reseller.
  3. Google representative — Chris Clements asked follow-up questions about reseller evaluation, agreement terms, and guidance SSL.com would provide to resellers.
  4. SSL.com — SSL.com described its reseller model, its RVP program, and how larger customers can use branded SubCAs.
  5. Google representative — Chris Clements asked for more detail on Certificate Services accounts, subscriber identity, and reseller agreement terms.
  6. SSL.com — SSL.com said it had no indication e-Tugra generated private keys and that e-Tugra had never generated or stored private keys for SSL.com subscribers in its portal.
  7. SSL.com — SSL.com defined a Certificate Services Account as a username/email and password used to access the SSL.com certificate portal and said password reset codes were sent directly by SSL.com.
  8. Google representative — Chris Clements thanked SSL.com for the responses and asked to be notified when the planned guidance and agreement updates were completed.
  9. SSL.com — SSL.com said it had scheduled a meeting to decide timelines for the guidance and agreement work and would post them by June 23.
  10. SSL.com — SSL.com announced timelines for reseller guidance, agreement updates, and a collaborative white paper on branded SubCAs.
  11. Google representative — Chris Clements said the plan was reasonable and suggested the bug be moved to Resolved/Invalid while progress continued to be tracked.
  12. SSL.com — SSL.com said the reseller guidance article was in final review and would be publicly released by the end of the week.
  13. SSL.com — SSL.com said the reseller guidance article had been published and that the other initiatives were still progressing.
  14. SSL.com — SSL.com reported progress on the white paper, including CCADB analysis, a survey, and a draft of good practices.
  15. SSL.com — SSL.com invited the community to review the Lessons Learned Whitepaper draft and later corrected the publication timeline.
  16. SSL.com — SSL.com announced publication of the final Lessons Learned White Paper.
  17. Mozilla representative — Ben Wilson said he saw no need to keep the bug open and suggested closing it.
Participants
Google representative SSL.com Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1850171 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-08-25 · Closed 2023-09-29 · 74% similar
SSL.com: S/MIME certificates issued prior to validation
#1871113 RESOLVED Ca Certificate Compliance Opened 2023-12-20 · Closed 2024-05-15 · 73% similar
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN
#1766525 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-04-26 · Closed 2023-02-22 · 56% similar
Entrust: TLS Certificate issued with a key that is impacted by the Close Primes vulnerability
#1802916 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-11-28 · Closed 2023-04-24 · 56% similar
Entrust: EV TLS Certificate incorrect jurisdiction
#1848240 RESOLVED Ca Certificate Compliance Incident Remediation Tracking Opened 2023-08-10 · Closed 2023-11-02 · 55% similar
TWCA: Undisclosed CA
#1848306 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2023-08-11 · Closed 2023-11-02 · 55% similar
TWCA: CA certificate without EKU
#1792231 RESOLVED Ca Certificate Compliance Certificate Misissuance Remediation Tracking Opened 2022-09-23 · Closed 2023-04-19 · 55% similar
Entrust: TLS Certificate issued with an incorrect state or province
#1839305 RESOLVED Ca Certificate Compliance Opened 2023-06-20 · Closed 2024-06-30 · 55% similar
Buypass: Domain validation method using externally operated DNS tools

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action