SSL.com third-party incident report for invalid subject stateOrProvince values in 20 certificates
This case is a third-party Certificate Problem Report about invalid subject stateOrProvinceName values in SSL.com certificates. SSL.com says a business-registry lookup tool used during organization validation auto-filled subject fields in the background and, in some cases, inserted malformed geographic information or caused an organization-name mismatch. The company says the feature was turned off during investigation, and it reported that all 20 affected certificates are now revoked. SSL.com also stated that there was no revocation delay. The latest update says development and code review for Action Items #3 and #4 are complete, both changes have been merged, and production deployment is scheduled for the next release window. SSL.com said it will re-verify the changes after deployment and that Action Item #5 remains in progress, with the next update requested for 2026-09-15.
- A business-registry lookup tool began auto-filling subject fields during organization validation.
- A third-party Certificate Problem Report was received about invalid stateOrProvinceName values in 3 OV TLS certificates.
- The business registry lookup feature flag was turned off.
- SSL.com said all 20 affected certificates were revoked and that remediation work on the action items was continuing.
- SSL.com — SSL.com posted a preliminary incident report saying it had received a third-party CPR and was investigating the root cause and scope.
- SSL.com — SSL.com said it was concluding its investigation and preparing the full incident report within the 14-day timeframe.
- SSL.com — SSL.com posted the full incident report describing the business-registry lookup tool, the affected certificate counts, and the revocation status at that time.
- SSL.com — SSL.com reposted the report with updates, said it found 20 total affected certificates, and said it would continue monitoring the bug and provide another update by 2026-08-21.
- SSL.com — SSL.com said it continues to monitor the bug, work on the action items, and will provide an update on or before 2026-08-28.
- SSL.com — SSL.com said development and code review for Action Items #3 and #4 were complete, both changes were merged, production deployment was scheduled, and Action Item #5 remained in progress.