← SSL.com cases
Bugzilla #1938236 Incident Revocation Issue

SSL.com: Failure to process CAA records from one SubCA

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com identified a compliance issue related to the failure to process CAA records for a CA certificate, affecting 57 TLS certificates, 7 of which were still active. This issue was discovered during a retroactive verification of post-ceremony actions as part of a previous bug. SSL.com remediated the issue by revoking the active certificates within 24 hours of discovery and submitted a preliminary incident report. A final incident report detailed the root cause, which included misconfiguration and peer review failures. SSL.com has since updated its documentation and processes to prevent future occurrences, and all action items have been completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.90 11 comments
Chronology
  1. SSL.com submitted a preliminary incident report after discovering a CAA configuration issue.
  2. SSL.com submitted a final incident report detailing the root cause and remediation steps.
  3. Mozilla plans to close the bug unless further issues arise.
Thread Activity
  1. SSL.com — SSL.com identified a CA certificate without proper CAA validation and reported 57 affected TLS certificates.
  2. SSL.com — Final incident report submitted, detailing the root cause and remediation actions.
  3. SSL.com — Incident report closure summary provided, confirming completion of all action items.
  4. Mozilla representative — Mozilla indicated plans to close the bug unless further issues arise.
Participants
SSL.com Mozilla representative
External References
Similar Local Cases
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 100% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1931636 RESOLVED Incident Opened 2024-11-15 · Closed 2025-02-12 · 100% similar
SSL.com: Delay in publishing OCSP responses
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 100% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1962809 RESOLVED Self Reported Incident Revocation Issue Opened 2025-04-25 · Closed 2025-07-28 · 99% similar
SSL.com: Expired certificate for a “Valid” Test Website
#1722089 RESOLVED Incident Opened 2021-07-23 · Closed 2023-02-22 · 98% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1790693 RESOLVED Self Reported Incident Revocation Issue Opened 2022-09-13 · Closed 2023-03-24 · 96% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1927532 RESOLVED Incident Opened 2024-10-28 · Closed 2025-08-26 · 96% similar
SSL.com: Issuance of certificates using keys previously reported as compromised
#2029230 RESOLVED Self Reported Incident Revocation Issue Opened 2026-04-03 · Closed 2026-05-28 · 91% similar
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action