← SSL.com cases
Bugzilla #1962809 Self Reported Incident Revocation Issue

SSL.com: Expired certificate for a “Valid” Test Website

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported an incident involving an expired certificate for a test website, which was discovered through a third-party Certificate Problem Report. The expired certificate was replaced with a valid one shortly after the issue was identified. SSL.com acknowledged that this incident violated section 2.2 of the TLS Baseline Requirements. Following the incident, SSL.com initiated an investigation and implemented several remediation actions, including enhancing their monitoring systems and creating a master list of all certificates to prevent future occurrences. The incident was resolved, and all action items have been completed as of July 2025.

Model: gpt-4o-mini Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 18:52 UTC Confidence: 0.90 12 comments
Chronology
  1. Third-party report submitted regarding the expired certificate.
  2. Full Incident Report submitted by SSL.com.
  3. Incident Closure Summary submitted, confirming all action items completed.
Thread Activity
  1. SSL.com — Preliminary Incident Report submitted detailing the expired certificate issue.
  2. SSL.com — Full Incident Report provided with a timeline and analysis of the incident.
  3. SSL.com — Incident Closure Summary submitted, detailing remediation actions taken.
Participants
SSL.com Google representative CCADB representative
External References
Similar Local Cases
#2029230 RESOLVED Self Reported Incident Revocation Issue Opened 2026-04-03 · Closed 2026-05-28 · 100% similar
SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#1938236 RESOLVED Incident Revocation Issue Opened 2024-12-18 · Closed 2025-02-28 · 99% similar
SSL.com: Failure to process CAA records from one SubCA
#1790693 RESOLVED Self Reported Incident Revocation Issue Opened 2022-09-13 · Closed 2023-03-24 · 96% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 89% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1974539 RESOLVED Self Reported Incident Revocation Issue Opened 2025-06-27 · Closed 2025-10-09 · 87% similar
DigiCert: DCV logging issue
#1942651 RESOLVED Self Reported Incident Policy Document Issue Opened 2025-01-20 · Closed 2025-02-14 · 87% similar
Sectigo / SSL.com: Late disclosure of updated SSL.com CP/CPS to CCADB
#2032482 ASSIGNED Ca Certificate Compliance Certificate Misissuance Problem Reporting Failure Audit Finding Opened 2026-04-16 Still Open · 86% similar
OATI: Misissuance detected by PKIMetal
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 84% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action