← SSL.com cases
Bugzilla #2057915 Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Validation Issue Repository Issue

SSL.com third-party incident report for invalid subject stateOrProvince values in 20 certificates

ASSIGNED SSL.com
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a third-party Certificate Problem Report about invalid subject stateOrProvinceName values in SSL.com certificates. SSL.com says a business-registry lookup tool used during organization validation auto-filled subject fields in the background and, in some cases, inserted malformed geographic information or caused an organization-name mismatch. The company says the feature was turned off during investigation, and it reported that all 20 affected certificates are now revoked. SSL.com also stated that there was no revocation delay. The latest update says development and code review for Action Items #3 and #4 are complete, both changes have been merged, and production deployment is scheduled for the next release window. SSL.com said it will re-verify the changes after deployment and that Action Item #5 remains in progress, with the next update requested for 2026-09-15.

Model: gpt-5.4-mini Generated: 2026-08-04 07:25 UTC Revised: 2026-08-30 06:02 UTC Confidence: 0.98 7 comments
Chronology
  1. A business-registry lookup tool began auto-filling subject fields during organization validation.
  2. A third-party Certificate Problem Report was received about invalid stateOrProvinceName values in 3 OV TLS certificates.
  3. The business registry lookup feature flag was turned off.
  4. SSL.com said all 20 affected certificates were revoked and that remediation work on the action items was continuing.
Thread Activity
  1. SSL.com — SSL.com posted a preliminary incident report saying it had received a third-party CPR and was investigating the root cause and scope.
  2. SSL.com — SSL.com said it was concluding its investigation and preparing the full incident report within the 14-day timeframe.
  3. SSL.com — SSL.com posted the full incident report describing the business-registry lookup tool, the affected certificate counts, and the revocation status at that time.
  4. SSL.com — SSL.com reposted the report with updates, said it found 20 total affected certificates, and said it would continue monitoring the bug and provide another update by 2026-08-21.
  5. SSL.com — SSL.com said it continues to monitor the bug, work on the action items, and will provide an update on or before 2026-08-28.
  6. SSL.com — SSL.com said development and code review for Action Items #3 and #4 were complete, both changes were merged, production deployment was scheduled, and Action Item #5 remained in progress.
Participants
SSL.com
External References
Similar Local Cases
#2065634 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Opened 2026-08-21 Still Open · 93% similar
SSL.com: Invalid combinations of countryName, stateOrProvinceName, and localityName attributes
#1942270 RESOLVED Revocation Issue Repository Issue Opened 2025-01-17 · Closed 2025-04-07 · 75% similar
SSL.com: Revocation process requires submission to a form that is unusable
#2060581 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Opened 2026-08-04 Still Open · 74% similar
Actalis: Issuance of Server TLS Certificates with id-kp-clientAuth against CPS
#2057318 ASSIGNED Externally Reported Incident Certificate Misissuance Problem Reporting Failure Opened 2026-07-23 Still Open · 72% similar
GlobalSign: Unicode replacement character issue in Subject
#2065895 ASSIGNED Ca Certificate Compliance Externally Reported Incident Certificate Misissuance Revocation Issue Opened 2026-08-23 Still Open · 72% similar
GlobalSign: StateOrProvince and LocalityName value inconsistency
#2056882 RESOLVED Externally Reported Incident Certificate Misissuance Opened By Ca Single Ca Owner Opened 2026-07-22 · Closed 2026-08-17 · 71% similar
D-Trust: EV Subordinate CA missing required cabfOrganizationIdentifier extension
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 71% similar
KIR S.A.: Invalid organizationName
#1942130 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2025-01-16 · Closed 2026-07-28 · 71% similar
HARICA: S/MIME certificate issuance without proper validation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action