Open Bug 2074980 Opened 2 days ago Updated 2 days ago

SSL.com: Failure to Post all Root and Intermediate CA certificates in Repository identified in CP/CPS

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

ASSIGNED

People

(Reporter: secauditor, Assigned: secauditor)

Details

(Whiteboard: [ca-compliance] [policy-failure] [disclosure-failure])

Preliminary Incident Report

Summary

  • Incident description:

On 2026-09-21, SSL.com's external auditors relayed a finding from the 2025–2026 audit period identifying that the 6 Root CA Certificates acquired from VikingCloud are described in the SSL.com CP/CPS as part of the SSL.com PKI but are not published in the SSL.com Repository.

SSL.com CP/CPS Section 2.2.5 states that "All Root and Intermediate CA Certificates utilized by the SSL.com PKI are available in the SSL.com Repository listed in §2.1," which Section 2.1 identifies as https://www.ssl.com/repository. The SSL.com CP/CPS has listed the following certificates as Root CA Certificates of the SSL.com PKI, effective 2026-03-06, since the publication of CP/CPS v1.29 on 2026-03-05: XRamp Global Certification Authority; SecureTrust CA; Secure Global CA; Trustwave Global Certification Authority; Trustwave Global ECC P256 Certification Authority; and Trustwave Global ECC P384 Certification Authority. While the Root CA certificates are present in CCADB, none of the 6 roots were present in the repository as of the end of the audit period, 2026-06-30.

  • Relevant policies:

SSL.com CP/CPS v1.29, Section 2.1 and Section 2.2.5:

2.1 Repositories

SSL.com maintains a central Repository to allow access to documents related to SSL.com’s policies and practices, including this CP/CPS, Subscriber and Relying Party agreements and root Certificates. SSL.com’s central Repository is available at https://www.ssl.com/repository.

SSL.com’s central Repository is maintained with resources sufficient to provide a commercially reasonable response time for access at all times. Distributed repositories that include at least the same type of information as the central repository may also exist.

2.2.5 SSL.com Root and Intermediate Certificates

All Root and Intermediate CA Certificates utilized by the SSL.com PKI are available in the SSL.com Repository listed in §2.1.

  • Source of incident disclosure: Audit.

SSl.com will post the full incident report on or before 2026-10-07.

Assignee: nobody → secauditor
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [policy-failure] [disclosure-failure]
You need to log in before you can comment on or make changes to this bug.