SSL.com delayed disclosure of Timestamping CA in CCADB
SSL.com reported that its auditor found a subordinate CA certificate, CN = SSL.com Timestamping Issuing RSA CA 2, that had been created on 2026-06-12 but was not disclosed to CCADB. The incident was identified during a comparison of the CA scope list used for SSL.com’s annual WebTrust audit against CCADB disclosures. SSL.com said the certificate should have been disclosed and that disclosure did not happen on time. The report cites CCADB v2.1 section 3.2, which requires CA owners to disclose subordinate CA certificates within 7 calendar days of issuance and before the CA begins issuing publicly-trusted certificates. SSL.com said it would post a full incident report on or before 2026-09-10.
- SSL.com Timestamping Issuing RSA CA 2 was created.
- The delayed CCADB disclosure was reported in a preliminary incident report.
- SSL.com — SSL.com said its auditor found the undisclosed subordinate CA certificate and stated that a full incident report would follow by 2026-09-10.