SSL.com: DCV bypass and issue fake certificates for any MX hostname

Discussion in 'privacy technology' started by FanJ, Apr 19, 2025.

  1. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,925
    Bug 1961406 Opened 19 hours ago Updated 3 hours ago

    https://bugzilla.mozilla.org/show_bug.cgi?id=1961406

    Cert revoked:
    https://crt.sh/?id=17926238129&opt=ocsp

    Thanks to Erik at security.nl :
    https://www.security.nl/posting/884827/Domain Validation en OCSP
     
  2. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,925
    Preliminary Incident Report is published.
    See above mentioned Bugzilla thread for the Summary:
    https://bugzilla.mozilla.org/show_bug.cgi?id=1961406
    See postings by Rebecca.

    Read there more for the details!!!

    Further down in that thread the other 10 certificates (that were mis-issued and have now been revoked) were given.
    ===

    One more quote:
     
    Last edited: Apr 22, 2025
  3. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,925
  4. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,925
  5. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,925
    The Full Incident Report has not yet been published. At least I don't see it yet mentioned in that Bugzilla thread.
    But, of course, it is not yet 02 May 2025. I do trust that Rebecca will post there.

    I'm just only posting because she posted there "SSL.com will post our Full Incident Report on or before 2025-05-02."
    So, we have to be patient.
     
  6. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,925
    Full Incident Report
    Posted by Rebecca about two hours ago in the Bugzilla thread:
    https://bugzilla.mozilla.org/show_bug.cgi?id=1961406

    Long post by Rebecca, with details, timeline and also details of the certs that were involved.

    Too much to quote, but in particular the part Relevant policies and the part Root Cause Analysis are important!

    Read there more.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.