SSL.com DCV bug caused mis-issuance via email-based domain validation
SSL.com reported a domain validation bug that caused misinterpretation of domain ownership in its email-based DCV flows, leading to mis-issued DV TLS certificates. The issue was first raised by a third-party security researcher, and SSL.com later confirmed that the problem affected BR 3.2.2.4.14 (Email to DNS TXT Contact) and also BR 3.2.2.4.2 (Email to Domain Contact). SSL.com said it disabled the affected validation method, revoked the reported certificate, identified additional affected certificates, and published incident reports and remediation updates. The company stated that all affected certificates had been revoked and that it deployed a patch plus new unit and integration tests for email-based validation methods. The bug was ultimately closed after SSL.com posted a report closure summary and requested closure.
- A callback change introduced a validation bug that could link certificate requests to the approver’s email domain instead of the requested domain.
- A third-party report identified a DCV bypass that led to mis-issuance of a DV TLS certificate.
- SSL.com disabled validation method 3.2.2.4.14 and revoked the reported certificate.
- SSL.com filed its full incident report and listed 11 affected certificates.
- SSL.com said it had completed expanded test coverage for email-based validation methods.
- SSL.com issued a report closure summary stating that all action items were complete.
- Community commenter — The reporter described a DCV bypass in SSL.com’s BR 3.2.2.4.14 flow and cited one affected certificate.
- SSL.com — SSL.com acknowledged the report and said it was investigating.
- SSL.com — SSL.com said it had disabled DCV method 3.2.2.4.14 for all SSL/TLS certificates while investigating.
- SSL.com — SSL.com posted a preliminary incident report saying the certificate had been revoked and that ten additional affected certificates had been found and revoked.
- SSL.com — SSL.com disclosed the list of all affected certificates and said full details would be provided in the final report.
- SSL.com — SSL.com said the issue did not affect systems and APIs used by Entrust.
- SSL.com — SSL.com said it supported 3.2.2.4.13 manually but had not automated it, and that only 3.2.2.4.4 and 3.2.2.4.14 were actively supported as automated email processes.
- SSL.com — SSL.com attached a list of affected certificates.
- SSL.com — SSL.com filed the full incident report, stating the bug affected 11 DV TLS certificates and that issuance using 3.2.2.4.14 had been disabled within two hours of the report.
- SSL.com — SSL.com said the flaw came from an external architectural change and that it had expanded test coverage for cases where the approver email domain differs from the validated domain.
- SSL.com — SSL.com reported that the patch for 3.2.2.4.14 had been deployed to staging and production, but the method remained disabled in production pending more testing.
- SSL.com — SSL.com said expanded unit and integration tests for email-based validation methods were completed and that all action items were complete.
- SSL.com — SSL.com provided statistics on email-based validation usage and described improvements to monitoring, audits, and internal controls.
- SSL.com — SSL.com posted a report closure summary and requested that the bug be closed.
- CCADB representative — CCADB issued a final call for comments and said the report would be closed around 2025-07-02.