SSL.com: Findings in 2023 audit
This case documents SSL.com’s 2023 WebTrust for CA Audit Report “Other matter” finding related to Certificate Problem Report (CPR) handling. For one of six selected certificate problem reports, SSL.com was not able to provide evidence that a preliminary report on its findings was distributed to both the subscriber and the entity who files the CPR within 24 hours of the report being filed. SSL.com’s root cause analysis states that the CPR involved a DV TLS certificate tied to an entity listed on the OFAC Sanction List, and that SSL.com’s documented CPR procedures were too complex for handling this specific, undocumented CPR type within the Baseline Requirements deadlines. SSL.com also found that its blocklisting regular expression was effective for the offending domain but not for its subdomains, which later allowed issuance of another certificate to a subdomain that was then revoked in a timely manner. SSL.com’s remediation actions included revamping/streamlining internal CPR procedures, introducing automated preliminary reporting to the subscriber (via a web form and thumbprint lookup), and introducing a blocklist checker tool. SSL.com reported that the automated preliminary reporting mechanism was implemented, tested/QA completed successfully, and deployed to production, and that all remediation actions for the bug were concluded. Mozilla indicated it would close the bug between Apr. 24–26, and the bug is marked RESOLVED with resolution FIXED.
- SSL.com opened a CA Certificate Compliance bug describing a 2023 audit finding about CPR preliminary reporting within 24 hours.
- SSL.com reported deployment and verification of the automated preliminary reporting mechanism and completion of remediation actions.
- Mozilla stated it would close the bug later the following week.
- SSL.com — SSL.com described the audit finding, root cause analysis, and action items to address CPR preliminary reporting and blocklisting effectiveness.
- SSL.com — SSL.com updated progress, stating action item 4 (blocklist checker tool) was completed.
- SSL.com — SSL.com reported action item 1 (revamp/streamline internal CPR procedures) was 70% done and expected to complete on time.
- SSL.com — SSL.com reported action item 1 completed and that automated preliminary reporting to the subscriber (action item 3) was underway.
- SSL.com — SSL.com provided design details for the automated preliminary reporting mechanism and stated an implementation timeline.
- SSL.com — SSL.com reported implementation of the mechanism completed and that testing/QA was underway.
- SSL.com — SSL.com reported testing/QA success, described the mechanism’s behavior, and stated production deployment would occur next week.
- SSL.com — SSL.com stated action item 3 was completed with deployment and verification, concluding remediation actions.
- Mozilla representative — Mozilla indicated it would close the bug later next week (Apr. 24–26).