SSL.com: S/MIME certificates issued prior to validation
SSL.com filed a preliminary incident report in Bugzilla after its Validation team noticed that two S/MIME IV+OV certificates were issued before the OV validation step was completed. SSL.com stated that the issue was discovered during normal validation tasks and that an internal ticket was created to notify relevant teams. After discovery, SSL.com instructed the Validation team to pause processing new S/MIME IV+OV certificate orders until a bug fix was deployed, and Software Engineering deployed an emergency fix to ensure OV completion before certificate generation email was sent. Compliance registered a Security Event ticket, performed retrospection, and identified a total of nine affected certificates (two initially noticed plus seven additional). SSL.com reported that it completed revocation of all affected certificates on 2023-08-23 and updated internal procedures for incident disclosure related to S/MIME certificates. Mozilla asked whether the issue was fully rectified to prevent recurrence, and SSL.com responded that the issue was fully rectified with preventative measures implemented; the bug was resolved as FIXED.
- SSL.com’s Validation team noticed S/MIME IV+OV certificates were issued before completion of the OV step.
- SSL.com completed retrospection and identified a total of nine affected S/MIME IV+OV certificates.
- SSL.com completed revocation of all affected certificates.
- SSL.com confirmed the issue was fully rectified and preventative measures were implemented.
- SSL.com — Filed a preliminary incident report describing the issuance of nine S/MIME certificates before validation was completed and the remediation steps taken.
- SSL.com — Reported no new information and stated the investigation was ongoing with an update planned for the following week.
- SSL.com — Reported a root cause analysis and stated the incident was due to reliance on a single developer for acceptance testing, with a process change to require 2+ developers.
- Mozilla representative — Asked whether the issue had been fully rectified to prevent recurrence.
- SSL.com — Confirmed the issue was fully rectified, the root cause addressed, and preventative measures implemented.
- Mozilla representative — Stated intent to close the case on 29-Sept-2023.