← SSL.com cases
Bugzilla #1932973 Certificate Misissuance Incident

SSL.com: CAA Empty set handling results in Wildcard issuance

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported a compliance issue regarding the issuance of a wildcard TLS certificate due to a misinterpretation of CAA records. The incident was triggered by a Certificate Problem Report received on November 15, 2024, which indicated that the absence of an 'issuewild' property was incorrectly interpreted as permission to issue the wildcard certificate. Following an investigation, SSL.com acknowledged the violation of their own Certificate Policy and promptly revoked the certificate. They implemented a patch to prevent future occurrences and updated their testing procedures to include this edge case. The final incident report was submitted on December 4, 2024, and all action items have been completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.90 23 comments
Chronology
  1. SSL.com received a Certificate Problem Report regarding a potential mis-processing of CAA records.
  2. The wildcard certificate was revoked.
  3. SSL.com submitted the Final Incident Report.
Thread Activity
  1. SSL.com — SSL.com submitted a Preliminary Incident Report regarding the CAA issue.
  2. SSL.com — SSL.com submitted the Final Incident Report detailing the incident and remediation steps.
  3. Mozilla representative — Mozilla requested SSL.com to update the incident report for more detail.
  4. SSL.com — SSL.com provided an Incident Report Closure Summary.
Participants
SSL.com Mozilla representative Mm representative
Similar Local Cases
#1931636 RESOLVED Incident Opened 2024-11-15 · Closed 2025-02-12 · 100% similar
SSL.com: Delay in publishing OCSP responses
#1938236 RESOLVED Incident Revocation Issue Opened 2024-12-18 · Closed 2025-02-28 · 100% similar
SSL.com: Failure to process CAA records from one SubCA
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 99% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1722089 RESOLVED Incident Opened 2021-07-23 · Closed 2023-02-22 · 97% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 96% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1927532 RESOLVED Incident Opened 2024-10-28 · Closed 2025-08-26 · 96% similar
SSL.com: Issuance of certificates using keys previously reported as compromised
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 95% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1850171 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-08-25 · Closed 2023-09-29 · 95% similar
SSL.com: S/MIME certificates issued prior to validation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action