← SSL.com cases
Bugzilla #1850171 Ca Certificate Compliance Certificate Misissuance

SSL.com: S/MIME certificates issued prior to validation

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com filed a preliminary incident report in Bugzilla after its Validation team noticed that two S/MIME IV+OV certificates were issued before the OV validation step was completed. SSL.com stated that the issue was discovered during normal validation tasks and that an internal ticket was created to notify relevant teams. After discovery, SSL.com instructed the Validation team to pause processing new S/MIME IV+OV certificate orders until a bug fix was deployed, and Software Engineering deployed an emergency fix to ensure OV completion before certificate generation email was sent. Compliance registered a Security Event ticket, performed retrospection, and identified a total of nine affected certificates (two initially noticed plus seven additional). SSL.com reported that it completed revocation of all affected certificates on 2023-08-23 and updated internal procedures for incident disclosure related to S/MIME certificates. Mozilla asked whether the issue was fully rectified to prevent recurrence, and SSL.com responded that the issue was fully rectified with preventative measures implemented; the bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.90 6 comments
Chronology
  1. SSL.com’s Validation team noticed S/MIME IV+OV certificates were issued before completion of the OV step.
  2. SSL.com completed retrospection and identified a total of nine affected S/MIME IV+OV certificates.
  3. SSL.com completed revocation of all affected certificates.
  4. SSL.com confirmed the issue was fully rectified and preventative measures were implemented.
Thread Activity
  1. SSL.com — Filed a preliminary incident report describing the issuance of nine S/MIME certificates before validation was completed and the remediation steps taken.
  2. SSL.com — Reported no new information and stated the investigation was ongoing with an update planned for the following week.
  3. SSL.com — Reported a root cause analysis and stated the incident was due to reliance on a single developer for acceptance testing, with a process change to require 2+ developers.
  4. Mozilla representative — Asked whether the issue had been fully rectified to prevent recurrence.
  5. SSL.com — Confirmed the issue was fully rectified, the root cause addressed, and preventative measures implemented.
  6. Mozilla representative — Stated intent to close the case on 29-Sept-2023.
Participants
SSL.com Mozilla representative
External References
Similar Local Cases
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 97% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 97% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1871113 RESOLVED Ca Certificate Compliance Opened 2023-12-20 · Closed 2024-05-15 · 96% similar
SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 95% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1961406 RESOLVED Certificate Misissuance Opened 2025-04-18 · Closed 2025-07-02 · 89% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1534145 RESOLVED Certificate Misissuance Opened 2019-03-10 · Closed 2023-02-22 · 80% similar
SSL.com: P-384 curve / ecdsa-with-SHA256 certificates
#1586795 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 80% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1532436 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2019-03-04 · Closed 2023-02-22 · 80% similar
Chunghwa Telecom: Test certificate with unregistered domain name

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action