← SSL.com cases
Bugzilla #1871113 Ca Certificate Compliance

SSL.com: Issuance of one Sponsored-Validated S/MIME certificate with organization information in givenName and surName of the subjectDN

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported a compliance issue regarding the issuance of a Sponsored-Validated S/MIME certificate that incorrectly included organization information in the givenName and surName fields of the subjectDN. This incident was triggered when a subscriber used the bulk order tool incorrectly, leading to a violation of the CA's Certificate Policy. The affected certificate was issued on December 14, 2023, and was revoked shortly after the issue was identified on December 18, 2023. SSL.com has since implemented corrective actions, including updates to the bulk order tool and public documentation to prevent similar occurrences in the future. The case has been resolved with all action items completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:48 UTC Confidence: 0.90 15 comments
Chronology
  1. A Sponsored-Validated S/MIME certificate was issued with incorrect subject information.
  2. The certificate was revoked after detection during a routine check.
  3. All action items related to the incident have been completed.
Thread Activity
  1. SSL.com — SSL.com disclosed the incident and provided a detailed report of the events leading to the misissuance.
  2. SSL.com — Guidance for bulk-ordering Organization-Validated S/MIME certificates was published.
  3. SSL.com — A wizard was deployed to guide users through the bulk ordering process.
  4. SSL.com — SSL.com requested closure of the report after completing all action items.
Participants
SSL.com Community commenter Mozilla representative
External References
Similar Local Cases
#1850171 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-08-25 · Closed 2023-09-29 · 96% similar
SSL.com: S/MIME certificates issued prior to validation
#1886406 RESOLVED Ca Certificate Compliance Opened 2024-03-20 · Closed 2024-08-28 · 81% similar
Hongkong Post: TLS certificates with Certificate Policies extension that does not assert http scheme
#1716123 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-06-12 · Closed 2024-05-25 · 80% similar
e-commerce monitoring GmbH: CN domain not in SAN
#1883416 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2024-03-04 · Closed 2024-08-28 · 78% similar
Certigna: TLS certificates with Basic constraint non-critical
#1714968 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-07 · Closed 2023-02-22 · 77% similar
GlobalSign: Incorrect RegNumber-Org Type combination
#1887096 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2024-03-22 · Closed 2024-09-06 · 76% similar
Chunghwa Telecom: Wrong Extended Key Usage setting by GTLSCA
#1839305 RESOLVED Ca Certificate Compliance Opened 2023-06-20 · Closed 2024-06-30 · 76% similar
Buypass: Domain validation method using externally operated DNS tools
#1815355 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2023-02-07 · Closed 2023-08-16 · 76% similar
Asseco DS / Certum: Cross-Signed non-EV-audited root with an EV-enabled root

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action