← SSL.com cases
Bugzilla #1927532 Certificate Problem Report

SSL.com: Issuance of certificates using keys previously reported as compromised

RESOLVED FIXED SSL.com
AI Summary

SSL.com faced a significant incident involving the issuance of TLS certificates using keys that had been previously reported as compromised. The issue was identified on October 25, 2024, when a Root Store Program representative alerted SSL.com about the mis-issuance, which violated established policies. In response, SSL.com promptly revoked the affected certificates and initiated an internal investigation. The investigation revealed that a manual process for blocking compromised keys was inadequate, leading to a series of corrective actions, including the implementation of automated systems to prevent future occurrences. SSL.com has committed to ongoing improvements in its processes and systems to enhance compliance and security.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Confidence: 0.95
Chronology
  1. SSL.com informed about mis-issuance of certificates.
  2. Affected certificates revoked within 24 hours.
  3. Final Incident Report submitted.
  4. All action items completed and report closure summary provided.
Participants
Rebecca Kelley Ryan Dickson Aaron Gable
Similar Local Cases
#1931636 RESOLVED Certificate Problem Report Opened 2024-11-15 · Closed 2025-02-12 · 59% similar
SSL.com: Delay in publishing OCSP responses
#1938236 RESOLVED Certificate Problem Report Opened 2024-12-18 · Closed 2025-02-28 · 58% similar
SSL.com: Failure to process CAA records from one SubCA
#1962809 RESOLVED Certificate Problem Report Opened 2025-04-25 · Closed 2025-07-28 · 58% similar
SSL.com: Expired certificate for a “Valid” Test Website
#1931615 RESOLVED Certificate Problem Report Opened 2024-11-15 · Closed 2024-12-03 · 56% similar
SSL.com: Entrust API and CAA checking
#1942270 RESOLVED Certificate Problem Report Opened 2025-01-17 · Closed 2025-04-07 · 55% similar
SSL.com: Revocation process requires submission to a form that is unusable
#1961406 RESOLVED Certificate Problem Report Opened 2025-04-18 · Closed 2025-07-02 · 53% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1534147 RESOLVED Certificate Problem Report Opened 2019-03-10 · Closed 2023-02-22 · 52% similar
SSL.com: Insufficient serial number entropy
#1790693 RESOLVED Certificate Problem Report Opened 2022-09-13 · Closed 2023-03-24 · 51% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action