← SSL.com cases
Bugzilla #1927532 Incident

SSL.com incident report on issuance using previously compromised keys

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com opened this case to report a compliance incident involving TLS certificates issued through its ACME service using keys that had previously been reported as compromised. The initial report said the issue was identified after a Chrome Root Store representative notified SSL.com on 2024-10-25, and SSL.com said it revoked the affected certificates, added the keys to a blocklist, and began an incident investigation. The final incident report stated that the problem was tied to SSL.com’s subscriber self-service revocation process when the reason was "keyCompromise", and that the same issue affected both ACME and RA Portal revocations. SSL.com reported that it completed remediation actions including automated scanning, alerting changes, internal procedure updates, and deployment of its CA software vendor’s native global blocklist feature. The case was later marked resolved, and SSL.com requested closure after stating that all disclosed action items had been completed.

Model: gpt-5.4-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:49 UTC Confidence: 0.98 33 comments
Chronology
  1. SSL.com was notified of TLS certificate issuance using keys previously reported as compromised.
  2. SSL.com revoked the initially identified affected certificates and added the keys to a blocklist.
  3. SSL.com filed its final incident report describing the affected certificate populations and root cause.
  4. SSL.com reported that its process now automatically adds keys involved in keyCompromise revocations to a global blocklist in real time.
  5. SSL.com submitted a closure summary stating that all disclosed action items were completed.
Thread Activity
  1. SSL.com — SSL.com filed a preliminary incident report describing mis-issuance involving previously compromised keys and said it had revoked the affected certificates and started an incident response.
  2. SSL.com — SSL.com filed its final incident report with impact details, root cause analysis, and remediation plans.
  3. Google representative — Asked for more detail on how affected certificates were identified, why the vendor was contacted, and how broader policy and process issues would be addressed.
  4. SSL.com — SSL.com clarified that it blocks all reported compromised keys, manually revokes existing certificates of the same subscriber, and may extend cascading revocations when possession is demonstrated.
  5. SSL.com — SSL.com reported completion of action items for revocation alerting and automated hourly scanning.
  6. SSL.com — SSL.com said its CA software vendor had released a version with native key blocklisting and that SSL.com would test and integrate it.
  7. SSL.com — SSL.com reported that it had tested and deployed the vendor blocklist and integrated it across its CA clusters.
  8. SSL.com — SSL.com posted a closure summary stating that the incident root cause, remediation, and ongoing commitments had been documented and that closure was requested.
Participants
SSL.com Google representative Internet Security Research Group Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1931636 RESOLVED Incident Opened 2024-11-15 · Closed 2025-02-12 · 99% similar
SSL.com: Delay in publishing OCSP responses
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 96% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1938236 RESOLVED Incident Revocation Issue Opened 2024-12-18 · Closed 2025-02-28 · 96% similar
SSL.com: Failure to process CAA records from one SubCA
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 91% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1579509 RESOLVED Incident Opened 2019-09-06 · Closed 2022-11-14 · 89% similar
SSL.com: Precertificates without corresponding certificates return OCSP value of "Unknown"
#1722089 RESOLVED Incident Opened 2021-07-23 · Closed 2023-02-22 · 87% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 78% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates
#1962809 RESOLVED Self Reported Incident Revocation Issue Opened 2025-04-25 · Closed 2025-07-28 · 72% similar
SSL.com: Expired certificate for a “Valid” Test Website

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action