← SSL.com cases
Bugzilla #1961406 Certificate Misissuance

SSL.com DCV bug caused mis-issuance via email-based domain validation

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported a domain validation bug that caused misinterpretation of domain ownership in its email-based DCV flows, leading to mis-issued DV TLS certificates. The issue was first raised by a third-party security researcher, and SSL.com later confirmed that the problem affected BR 3.2.2.4.14 (Email to DNS TXT Contact) and also BR 3.2.2.4.2 (Email to Domain Contact). SSL.com said it disabled the affected validation method, revoked the reported certificate, identified additional affected certificates, and published incident reports and remediation updates. The company stated that all affected certificates had been revoked and that it deployed a patch plus new unit and integration tests for email-based validation methods. The bug was ultimately closed after SSL.com posted a report closure summary and requested closure.

Model: gpt-5.4-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:52 UTC Confidence: 0.96 34 comments
Chronology
  1. A callback change introduced a validation bug that could link certificate requests to the approver’s email domain instead of the requested domain.
  2. A third-party report identified a DCV bypass that led to mis-issuance of a DV TLS certificate.
  3. SSL.com disabled validation method 3.2.2.4.14 and revoked the reported certificate.
  4. SSL.com filed its full incident report and listed 11 affected certificates.
  5. SSL.com said it had completed expanded test coverage for email-based validation methods.
  6. SSL.com issued a report closure summary stating that all action items were complete.
Thread Activity
  1. Community commenter — The reporter described a DCV bypass in SSL.com’s BR 3.2.2.4.14 flow and cited one affected certificate.
  2. SSL.com — SSL.com acknowledged the report and said it was investigating.
  3. SSL.com — SSL.com said it had disabled DCV method 3.2.2.4.14 for all SSL/TLS certificates while investigating.
  4. SSL.com — SSL.com posted a preliminary incident report saying the certificate had been revoked and that ten additional affected certificates had been found and revoked.
  5. SSL.com — SSL.com disclosed the list of all affected certificates and said full details would be provided in the final report.
  6. SSL.com — SSL.com said the issue did not affect systems and APIs used by Entrust.
  7. SSL.com — SSL.com said it supported 3.2.2.4.13 manually but had not automated it, and that only 3.2.2.4.4 and 3.2.2.4.14 were actively supported as automated email processes.
  8. SSL.com — SSL.com attached a list of affected certificates.
  9. SSL.com — SSL.com filed the full incident report, stating the bug affected 11 DV TLS certificates and that issuance using 3.2.2.4.14 had been disabled within two hours of the report.
  10. SSL.com — SSL.com said the flaw came from an external architectural change and that it had expanded test coverage for cases where the approver email domain differs from the validated domain.
  11. SSL.com — SSL.com reported that the patch for 3.2.2.4.14 had been deployed to staging and production, but the method remained disabled in production pending more testing.
  12. SSL.com — SSL.com said expanded unit and integration tests for email-based validation methods were completed and that all action items were complete.
  13. SSL.com — SSL.com provided statistics on email-based validation usage and described improvements to monitoring, audits, and internal controls.
  14. SSL.com — SSL.com posted a report closure summary and requested that the bug be closed.
  15. CCADB representative — CCADB issued a final call for comments and said the report would be closed around 2025-07-02.
Participants
Community commenter SSL.com GlobalSign nv-sa Google representative CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1932973 RESOLVED Certificate Misissuance Incident Opened 2024-11-22 · Closed 2025-04-07 · 95% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1724520 RESOLVED Certificate Misissuance Opened 2021-08-06 · Closed 2023-02-22 · 90% similar
SSL.com: Incorrect Domain Validation for 1 TLS certificate with FQDN having "www." string within domain labels
#1678720 RESOLVED Certificate Misissuance Opened 2020-11-20 · Closed 2023-02-22 · 89% similar
SSL.com: Wildcard DV certificate issued with a non-validated domain name
#1850171 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-08-25 · Closed 2023-09-29 · 89% similar
SSL.com: S/MIME certificates issued prior to validation
#1986968 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-09-04 · Closed 2026-04-06 · 87% similar
Financijska agencija (Fina): Mis-issued certificates
#1963456 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-04-29 · Closed 2025-07-25 · 85% similar
GoDaddy: CA Certificates with HTTPS URL in AIA Field
#1969296 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-05-29 · Closed 2025-07-22 · 85% similar
GoDaddy: Certificates with invalid embedded SCT signatures
#1963663 RESOLVED Incident Certificate Misissuance Opened 2025-04-30 · Closed 2025-06-12 · 85% similar
Certigna: Multiple Reserved Certificate Policy Identifiers in CA certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action