SSL.com: Expired certificate for a “Valid” Test Website
SSL.com reported an incident involving an expired certificate for a test website, which was discovered through a third-party Certificate Problem Report. The expired certificate was replaced with a valid one shortly after the issue was identified. SSL.com acknowledged that this incident violated section 2.2 of the TLS Baseline Requirements. Following the incident, SSL.com initiated an investigation and implemented several remediation actions, including enhancing their monitoring systems and creating a master list of all certificates to prevent future occurrences. The incident was resolved, and all action items have been completed as of July 2025.
- Third-party report submitted regarding the expired certificate.
- Full Incident Report submitted by SSL.com.
- Incident Closure Summary submitted, confirming all action items completed.
- SSL.com — Preliminary Incident Report submitted detailing the expired certificate issue.
- SSL.com — Full Incident Report provided with a timeline and analysis of the incident.
- SSL.com — Incident Closure Summary submitted, detailing remediation actions taken.