SSL.com: Incorrect Open MPIC Lambda implementation by EJBCA ACME Service
SSL.com reported an incident involving an incorrect Open MPIC Lambda implementation by the EJBCA ACME service, which allowed domain control validation (DCV) to be completed based solely on remote Network Perspectives. This issue was disclosed following a third-party report received on April 2, 2026. SSL.com confirmed the compliance failure and executed a mass revocation plan, successfully revoking approximately 1.7 million affected certificates within 24 hours. The CA has since implemented a fix and updated its testing procedures to prevent future occurrences. A full incident report was submitted, and SSL.com has committed to ongoing compliance with CA/B Forum requirements.
- Third-party report received regarding potential compliance issue.
- Mass revocation of affected certificates completed.
- Report closure summary submitted, detailing remediation actions.
- SSL.com — Preliminary incident report filed to Bugzilla.
- SSL.com — Full incident report submitted with detailed timeline and impact.
- SSL.com — Report closure summary submitted, confirming completion of remediation actions.