SSL.com: Revocation process requires submission to a form that is unusable
This case involves a report from a user about difficulties in reporting a compromised certificate to SSL.com. The user attempted to use the provided online form but found it ambiguous regarding the required 'Certificate Thumbprint'. SSL.com acknowledged the report and confirmed that the compromised certificate was revoked within the required timeline. However, they also recognized the need for usability improvements in their reporting mechanisms. SSL.com has since updated their CPR submission form to accept multiple certificate identifiers and provide clearer guidance for users. The case has been marked as 'invalid' as SSL.com complied with the necessary procedures.
- User reported a certificate with a compromised key to SSL.com.
- SSL.com confirmed the compromised certificate was revoked.
- SSL.com updated their CPR submission form for better usability.
- Hboeck representative — Reported issues with SSL.com's certificate revocation process.
- SSL.com — Confirmed that the compromised certificate was revoked and acknowledged usability issues.
- SSL.com — Announced updates to the CPR submission form to improve user experience.
- Mozilla representative — Intended to close the bug as invalid.