SSL.com incident report on issuance using previously compromised keys
SSL.com opened this case to report a compliance incident involving TLS certificates issued through its ACME service using keys that had previously been reported as compromised. The initial report said the issue was identified after a Chrome Root Store representative notified SSL.com on 2024-10-25, and SSL.com said it revoked the affected certificates, added the keys to a blocklist, and began an incident investigation. The final incident report stated that the problem was tied to SSL.com’s subscriber self-service revocation process when the reason was "keyCompromise", and that the same issue affected both ACME and RA Portal revocations. SSL.com reported that it completed remediation actions including automated scanning, alerting changes, internal procedure updates, and deployment of its CA software vendor’s native global blocklist feature. The case was later marked resolved, and SSL.com requested closure after stating that all disclosed action items had been completed.
- SSL.com was notified of TLS certificate issuance using keys previously reported as compromised.
- SSL.com revoked the initially identified affected certificates and added the keys to a blocklist.
- SSL.com filed its final incident report describing the affected certificate populations and root cause.
- SSL.com reported that its process now automatically adds keys involved in keyCompromise revocations to a global blocklist in real time.
- SSL.com submitted a closure summary stating that all disclosed action items were completed.
- SSL.com — SSL.com filed a preliminary incident report describing mis-issuance involving previously compromised keys and said it had revoked the affected certificates and started an incident response.
- SSL.com — SSL.com filed its final incident report with impact details, root cause analysis, and remediation plans.
- Google representative — Asked for more detail on how affected certificates were identified, why the vendor was contacted, and how broader policy and process issues would be addressed.
- SSL.com — SSL.com clarified that it blocks all reported compromised keys, manually revokes existing certificates of the same subscriber, and may extend cascading revocations when possession is demonstrated.
- SSL.com — SSL.com reported completion of action items for revocation alerting and automated hourly scanning.
- SSL.com — SSL.com said its CA software vendor had released a version with native key blocklisting and that SSL.com would test and integrate it.
- SSL.com — SSL.com reported that it had tested and deployed the vendor blocklist and integrated it across its CA clusters.
- SSL.com — SSL.com posted a closure summary stating that the incident root cause, remediation, and ongoing commitments had been documented and that closure was requested.