← SSL.com cases
Bugzilla #1850171 Certificate Misissuance

SSL.com: S/MIME certificates issued prior to validation

RESOLVED FIXED SSL.com
AI Summary

SSL.com reported the issuance of 9 S/MIME certificates before the completion of the validation process. The issue was identified during routine validation tasks, prompting an internal investigation and subsequent actions to halt further mis-issuances. A root cause analysis revealed that reliance on a single developer for acceptance testing contributed to the incident. The software engineering team implemented fixes to prevent future occurrences, and all affected certificates were revoked by August 23, 2023.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Confidence: 1.00
Chronology
  1. Update of RA Portal for human review of identity validations
  2. Validation team noticed mis-issuance of certificates
  3. Revocation of all affected certificates completed
  4. Issue fully rectified and preventative measures implemented
Participants
secauditor@ssl.com bwilson@mozilla.com
External References
Similar Local Cases
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 69% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1750631 RESOLVED Certificate Misissuance Opened 2022-01-17 · Closed 2024-06-30 · 69% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 68% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1871113 RESOLVED Certificate Misissuance Opened 2023-12-20 · Closed 2024-05-15 · 65% similar
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN
#1986968 RESOLVED Certificate Misissuance Opened 2025-09-04 · Closed 2026-04-06 · 52% similar
Financijska agencija (Fina): Mis-issued certificates
#1662382 RESOLVED Certificate Misissuance Opened 2020-09-01 · Closed 2023-02-22 · 51% similar
GDCA: Incorrect Value in organizationName Field
#1711432 RESOLVED Certificate Misissuance Opened 2021-05-17 · Closed 2023-02-22 · 50% similar
Telekom Security: Certificate with invalid FQDN
#1909948 RESOLVED Certificate Misissuance Opened 2024-07-25 · Closed 2024-10-31 · 49% similar
GoDaddy: Edge Case for Data Reuse Outside of Timeframes

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action