← SSL.com cases
Bugzilla #1961406 Certificate Problem Report

SSL.com: DCV bypass and issue fake certificates for any MX hostname

CLOSED FIXED SSL.com
AI Summary

SSL.com experienced a significant issue with its domain validation process, leading to the mis-issuance of eleven certificates due to an incorrect implementation of the Domain Control Validation (DCV) method. The bug allowed SSL.com to mistakenly verify domains based on the email domain of the approver rather than the actual domain being validated. Following the identification of the issue, SSL.com promptly disabled the affected validation method, revoked the mis-issued certificates, and implemented corrective measures, including enhanced testing protocols to prevent similar occurrences in the future. The incident was reported by a third party and has been addressed with a commitment to improve compliance and operational practices.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Confidence: 0.95
Chronology
  1. Initial bug report filed by a third party.
  2. Preliminary incident report released by SSL.com.
  3. Full incident report published detailing the bug and its impact.
  4. Report closure summary provided by SSL.com.
  5. SSL.com requests closure of the bug.
Participants
ragtime_knoll5n@icloud.com rebeccak@ssl.com arvid.vermote@globalsign.com tjtncks@gmail.com chrome-root-program@google.com secauditor@ssl.com
External References
Similar Local Cases
#1932973 RESOLVED Certificate Problem Report Opened 2024-11-22 · Closed 2025-04-07 · 65% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1957140 RESOLVED Certificate Problem Report Opened 2025-03-28 · Closed 2025-08-11 · 65% similar
SSL.com: "unknown" OCSP response for issued certificates
#2029230 RESOLVED Certificate Problem Report Opened 2026-04-03 · Closed 2026-05-28 · 63% similar
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#1722089 RESOLVED Certificate Problem Report Opened 2021-07-23 · Closed 2023-02-22 · 61% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1719916 RESOLVED Certificate Problem Report Opened 2021-07-09 · Closed 2023-02-22 · 61% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1790693 RESOLVED Certificate Problem Report Opened 2022-09-13 · Closed 2023-03-24 · 58% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1938236 RESOLVED Certificate Problem Report Opened 2024-12-18 · Closed 2025-02-28 · 57% similar
SSL.com: Failure to process CAA records from one SubCA
#1666872 RESOLVED Certificate Problem Report Opened 2020-09-23 · Closed 2023-02-22 · 56% similar
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action