A brief explanation regarding the recent revocation event that concluded on Thursday, September 10, 2026.
An issue was identified in our certificate issuance workflow, resulting in a deviation from the CA/Browser Forum (CABF) compliance requirements for a certain group of certificates. The deviation impacted how validation was corroborated using Multi-Perspective Issuance Corroboration (MPIC).
Primary domain control validation was performed for the affected certificates. What could not be confirmed is that we met the required quorum of remote perspectives at the time of validation.
This incident does not reflect a security issue. There is no indication of compromise or of incorrect domain validation.
As a result, and in accordance with industry compliance requirements including the CABF Baseline Requirements and browser root store programs, we were required to revoke the affected certificates. Revocation was completed within the required timeline on September 10, 2026. This action ensured continued industry compliance and SSL.com’s commitment to maintaining the integrity of the WebPKI trust ecosystem.
This issue is limited to a subset of OV and EV TLS certificates whose domain validation was completed after the MPIC enforcement date of March 15, 2025. Subscribers with affected certificates were notified by email.
We will continue to provide updates, and a final report with additional updates can be found here.
Affected certificates must be replaced. Please let us know if you have any questions or need assistance with reissuance. Contact our support team or chat with us in the lower-right corner of this page.
