← SSL.com cases
Bugzilla #1938236 Certificate Problem Report

SSL.com: Failure to process CAA records from one SubCA

RESOLVED FIXED SSL.com
AI Summary

SSL.com identified a failure to properly configure the CAA validator for a CA certificate, affecting 57 TLS certificates, of which 7 were still active. The issue was discovered during a retroactive verification process and was promptly remediated, with all active certificates revoked within 24 hours. The root cause was attributed to a misconfiguration during the setup process and insufficient peer review due to the complexity of changes made. SSL.com has since updated its procedures to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Confidence: 0.95
Chronology
  1. Discovered misconfiguration of CAA validator
  2. Revoked all 7 active certificates
  3. Completed action items to improve configuration processes
  4. Incident report closure expected
Participants
Rebecca Kelley secauditor@ssl.com bwilson@mozilla.com
External References
Similar Local Cases
#1722089 RESOLVED Certificate Problem Report Opened 2021-07-23 · Closed 2023-02-22 · 69% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1932973 RESOLVED Certificate Problem Report Opened 2024-11-22 · Closed 2025-04-07 · 67% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1719916 RESOLVED Certificate Problem Report Opened 2021-07-09 · Closed 2023-02-22 · 66% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1666872 RESOLVED Certificate Problem Report Opened 2020-09-23 · Closed 2023-02-22 · 65% similar
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate
#1790693 RESOLVED Certificate Problem Report Opened 2022-09-13 · Closed 2023-03-24 · 65% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1800753 RESOLVED Certificate Problem Report Opened 2022-11-15 · Closed 2023-07-21 · 64% similar
SSL.com: Delayed revocation of certificate with weak key
#1931636 RESOLVED Certificate Problem Report Opened 2024-11-15 · Closed 2025-02-12 · 59% similar
SSL.com: Delay in publishing OCSP responses
#2029230 RESOLVED Certificate Problem Report Opened 2026-04-03 · Closed 2026-05-28 · 59% similar
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action