← SSL.com cases
Bugzilla #1962800 Revocation Issue

SSL.com: Revocation due to keyCompromise while keeping other TLS certs with the same public key unrevoked

RESOLVED INVALID SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened after a SSL.com subscriber revoked a certificate due to keyCompromise, while SSL.com left other TLS certificates sharing the same public key unrevoked. The reporter expected SSL.com to revoke all certificates with the same public key when a subscriber requests a keyCompromise revocation. Mozilla staff discussion noted that a CA is only required to revoke all certificates sharing a key when the CA obtains evidence that the subscriber’s private key suffered a key compromise, and that some revocation request mechanisms (including ACME) allow subscribers to request a revocation reason without providing evidence/proof of key compromise. The discussion referenced Mozilla’s Revocation Reasons guidance about how revocation scope depends on whether the subscriber has proven possession of the private key. The reporter indicated they would try to close the bug. The bug is currently marked RESOLVED with resolution INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:52 UTC Confidence: 0.62 3 comments
Chronology
  1. A SSL.com subscriber revoked a certificate due to keyCompromise, but SSL.com left other TLS certificates with the same public key unrevoked.
Thread Activity
  1. Community commenter — Reported that a subscriber keyCompromise revocation occurred but SSL.com kept other TLS certificates with the same public key unrevoked, and expected all such certificates to be revoked.
  2. Internet Security Research Group — Explained that the CA’s obligation to revoke all certificates sharing a key depends on whether the CA has evidence of key compromise, and cited Mozilla guidance and ACME behavior regarding revocation reason requests.
  3. Community commenter — Acknowledged the explanation and said they would try to close the bug.
Participants
Community commenter Internet Security Research Group
Similar Local Cases
#1942270 RESOLVED Revocation Issue Repository Issue Opened 2025-01-17 · Closed 2025-04-07 · 79% similar
SSL.com: Revocation process requires submission to a form that is unusable
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 66% similar
e-commerce monitoring GmbH: SCT in precertificate
#1484798 RESOLVED Ca Security Vulnerability Revocation Issue Opened 2018-08-20 · Closed 2024-05-09 · 61% similar
DigiCert: *.sslsimplified.com compromised private key
#1942455 RESOLVED Revocation Issue Opened 2025-01-18 · Closed 2025-03-18 · 61% similar
DigiCert: inconsistent revocation / OCSP / CRL behavior
#1910451 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2024-08-21 · 60% similar
Sectigo: Missing character in subject:organizationName attribute value
#1320943 RESOLVED Revocation Issue Repository Issue Opened 2016-11-29 · Closed 2022-11-14 · 59% similar
Add revoked certificate Certification Authority of WoSign G2 issued by Certum CA root to OneCRL
#1912225 RESOLVED Revocation Issue Opened 2024-08-08 · Closed 2024-09-26 · 58% similar
Sectigo: HTML encoded characters in subject attribute values
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 58% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action