← SSL.com cases
Bugzilla #2029230 Certificate Problem Report

SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service

RESOLVED FIXED SSL.com
AI Summary

SSL.com reported an incident involving an incorrect Open MPIC Lambda implementation by the EJBCA ACME service, which allowed domain control validation (DCV) to be completed based solely on remote Network Perspectives. This was a violation of the Baseline Requirements regarding Multi-Perspective Issuance Corroboration. The issue was identified through a third-party report, leading to the revocation of approximately 1.7 million affected certificates within 24 hours. SSL.com has since implemented a fix and updated its testing procedures to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:00 UTC Confidence: 0.95
Chronology
  1. Third-party report received regarding potential compliance issue.
  2. Mass revocation of affected certificates completed.
  3. Remediation actions reported as completed.
  4. Report closure summary submitted.
Participants
secauditor@ssl.com cainfo@ml.secom-sts.co.jp antti.backman@teliacompany.com trusten.sec@gmail.com incident-reporting@ccadb.org
External References
Similar Local Cases
#1957140 RESOLVED Certificate Problem Report Opened 2025-03-28 · Closed 2025-08-11 · 65% similar
SSL.com: "unknown" OCSP response for issued certificates
#1961406 RESOLVED Certificate Problem Report Opened 2025-04-18 · Closed 2025-07-02 · 63% similar
SSL.com: DCV bypass and issue fake certificates for any MX hostname
#1722089 RESOLVED Certificate Problem Report Opened 2021-07-23 · Closed 2023-02-22 · 60% similar
SSL.com: Issuance of 3 EV TLS certificates without 2-person validation of the organization information
#1719916 RESOLVED Certificate Problem Report Opened 2021-07-09 · Closed 2023-02-22 · 60% similar
SSL.com: Issuance of an EV TLS certificate with incorrect O Field Value
#1932973 RESOLVED Certificate Problem Report Opened 2024-11-22 · Closed 2025-04-07 · 60% similar
SSL.com: CAA Empty set handling results in Wildcard issuance
#1790693 RESOLVED Certificate Problem Report Opened 2022-09-13 · Closed 2023-03-24 · 59% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1938236 RESOLVED Certificate Problem Report Opened 2024-12-18 · Closed 2025-02-28 · 59% similar
SSL.com: Failure to process CAA records from one SubCA
#1666872 RESOLVED Certificate Problem Report Opened 2020-09-23 · Closed 2023-02-22 · 58% similar
SSL.com: Insufficient validation evidence for the localityName attribute of an OV certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action