← SSL.com cases
Bugzilla #2029230 Self Reported Incident Revocation Issue

SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service

RESOLVED FIXED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

SSL.com reported an incident involving an incorrect Open MPIC Lambda implementation by the EJBCA ACME service, which allowed domain control validation (DCV) to be completed based solely on remote Network Perspectives. This issue was disclosed following a third-party report received on April 2, 2026. SSL.com confirmed the compliance failure and executed a mass revocation plan, successfully revoking approximately 1.7 million affected certificates within 24 hours. The CA has since implemented a fix and updated its testing procedures to prevent future occurrences. A full incident report was submitted, and SSL.com has committed to ongoing compliance with CA/B Forum requirements.

Model: gpt-4o-mini Generated: 2026-06-13 21:00 UTC Revised: 2026-06-16 18:53 UTC Confidence: 0.85 17 comments
Chronology
  1. Third-party report received regarding potential compliance issue.
  2. Mass revocation of affected certificates completed.
  3. Report closure summary submitted, detailing remediation actions.
Thread Activity
  1. SSL.com — Preliminary incident report filed to Bugzilla.
  2. SSL.com — Full incident report submitted with detailed timeline and impact.
  3. SSL.com — Report closure summary submitted, confirming completion of remediation actions.
Participants
SSL.com Ml representative Teliacompany representative Community commenter CCADB representative
External References
Similar Local Cases
#1962809 RESOLVED Self Reported Incident Revocation Issue Opened 2025-04-25 · Closed 2025-07-28 · 100% similar
SSL.com: Expired certificate for a “Valid” Test Website
#1790693 RESOLVED Self Reported Incident Revocation Issue Opened 2022-09-13 · Closed 2023-03-24 · 98% similar
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
#1938236 RESOLVED Incident Revocation Issue Opened 2024-12-18 · Closed 2025-02-28 · 91% similar
SSL.com: Failure to process CAA records from one SubCA
#2029643 RESOLVED Self Reported Incident Revocation Issue Certificate Misissuance Opened 2026-04-06 · Closed 2026-05-22 · 89% similar
HARICA: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
#1750631 RESOLVED Incident Revocation Issue Opened 2022-01-17 · Closed 2024-06-30 · 87% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#2007070 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2025-12-19 · Closed 2026-03-30 · 86% similar
SECOM: Non conformant SCT Encoding Due to SCT Modification by Cybertrust Japan (CTJ)
#2021550 RESOLVED Self Reported Incident Revocation Issue Opened 2026-03-06 · Closed 2026-03-26 · 85% similar
SECOM: 2025 S/MIME CA Modified Opinion Report of Cybertrust Japan (CTJ)
#2012274 RESOLVED Self Reported Incident Certificate Misissuance Revocation Issue Opened 2026-01-24 · Closed 2026-03-08 · 82% similar
Chunghwa Telecom: Issuance of certificate using keys previously reported as compromised

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action