SSL.com third-party Certificate Problem Report about invalid geographic subject attribute combinations, with remediation completed for action item #1
SSL.com opened this case after receiving a third-party Certificate Problem Report about invalid combinations of countryName, stateOrProvinceName, and localityName in OV TLS certificates. SSL.com said its investigation found manual errors that were not caught by existing monitoring, and it identified one additional unexpired OV TLS certificate during review. The company reported that the certificates reported in the CPR were revoked, and that all affected certificates were revoked within 5 days of their respective discovery. SSL.com also said it found the root cause was the absence of a technical control to enforce valid geographic combinations. In the latest update, SSL.com said action item #1 was deployed on 2026-09-11 and is now complete, while action items #3 and #4 remain in progress and are on track for completion by 2026-10-31. The bug remains open and SSL.com said it will continue to monitor the thread for comments or questions.
- Earliest discovered OV TLS certificate with mismatched geographic subject information was issued.
- SSL.com received a third-party Certificate Problem Report about four OV TLS certificates with invalid geographic subject attribute combinations.
- The four certificates reported in the CPR were revoked.
- SSL.com confirmed one additional misissued OV TLS certificate during manual review.
- SSL.com posted its Full Incident Report.
- SSL.com reported that remediation action item #1 had begun deployment in staging and was being tested before production rollout.
- SSL.com said action item #1 was deployed and complete, and that action items #3 and #4 remained in progress.
- SSL.com — SSL.com said it had received a third-party CPR, was investigating root cause and scope, and would provide full certificate details in the full report.
- SSL.com — SSL.com said it would post its Full Incident Report on or before 2026-09-04.
- SSL.com — SSL.com posted the Full Incident Report, describing the investigation, revocations, root cause, and planned blocking control.
- SSL.com — SSL.com said remediation action item #1 had begun deployment in staging and was being thoroughly tested before production.
- SSL.com — SSL.com said action item #1 was deployed and complete, action items #3 and #4 were still in progress, and the next update was planned for 2026-10-15.