{"id":3485,"date":"2025-04-25T11:50:52","date_gmt":"2025-04-25T11:50:52","guid":{"rendered":"https:\/\/certera.com\/blog\/?p=3485"},"modified":"2025-05-26T11:22:42","modified_gmt":"2025-05-26T11:22:42","slug":"unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw","status":"publish","type":"post","link":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/","title":{"rendered":"Unauthorized Certificates Issued for Alibaba Cloud Due to SSL.com CA Flaw"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/gbhackers.com\/fake-certificate-issued-for-alibaba-cloud\/\"><\/a>A critical vulnerability in the SSL.com domain validation process allowed unauthorized parties to get the certificates on behalf of you or your organisation. SSL.com is one of the famous Certificate Authorities (CA) trusted by all major browsers.<\/p>\n\n\n\n<p class=\"quote-section wp-block-paragraph\">This Vulnerability is reported by <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1961406\">security researchers<\/a>; in their demonstration, they showed how an attacker can misuse it to get a fraudulent certificate. He did a <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1961406\">POC<\/a> (proof of concept) of this bug on aliyun.com, the official website for Alibaba Cloud, one of the largest cloud companies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-understanding-the-poc\">Understanding the POC<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSSL.com totally messed up their domain validation checks,\u201d the researcher explained. They used a method called Email to DNS TXT Contact, but here\u2019s the problem. They ended up trusting the wrong part of the domain; just because an email showed up, they assumed the whole domain was legit. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Big mistake. That\u2019s not how validation is supposed to work. And it opened the door for attackers to sneak in and get trusted certificates they never should\u2019ve had.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The researcher figured out a loophole in how SSL.com validates domain ownership using a method called DCV (Domain Control Validation). This method uses email-based validation tied to DNS records. So here\u2019s what the researcher did. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Also Read:<\/strong> <a href=\"https:\/\/certera.com\/blog\/end-of-whois-based-dcv-methods-what-you-need-to-know-and-how-to-transition\/\">The End of WHOIS-Based DCV Methods: What You Need to Know and How to Transition<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Created a test domain, something harmless, under their control. Added a special DNS TXT record to it: _validation-contactemail with an @aliyun.com email address.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wait\u2026 what? Yes, they were using a test domain, but they added an email address from aliyun.com (Alibaba Cloud\u2019s official domain) inside the DNS record. The researcher went to SSL.com and requested a certificate for their test domain. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During the process, SSL.com offered a list of email approvers. Guess what was on the list? Their @aliyun.com email! SSL.com sent a verification code (the DCV random value) to that email. The researcher clicked the link. Done. Validation complete.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Also Read:<\/strong> <a href=\"https:\/\/certera.com\/blog\/digicert-elevates-industry-standards-with-new-open-source-dcv-library\/\">DigiCert Elevates Industry Standards with New Open-Source DCV Library<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SSL.com mistakenly thought the researcher had verified ownership of aliyun.com, just because the email address used had that domain. They automatically added aliyun.com to the researcher\u2019s list of verified domains. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>With that, the researcher was now able to issue real, trusted SSL certificates for:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>aliyun.com<\/li>\n\n\n\n<li>www.aliyun.com<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-did-ssl-com-react\">How Did SSL.com React?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To their credit, SSL.com moved fast. They immediately disabled that validation method. Revoked the wrongly issued certificates. Investigated and found 10 other certificates issued using the same flawed logic \u2014 and revoked those too. <\/p>\n\n\n\n<p class=\"quote-section wp-block-paragraph\">They later admitted: \u201cThe validation process was broken. It incorrectly verified domains just based on the hostname in the approver\u2019s email.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Here are some of the top domains whose SSL certificates were wrongly issued and then revoked by SSL.com:<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-aliyun-com\">aliyun.com<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Alibaba Cloud. One of the biggest cloud providers in Asia. The researcher was able to get a certificate for this domain \u2014 the same one used for webmail, cloud infrastructure, and enterprise services.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-medinet-ca\">*.medinet.ca<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A wildcard certificate for Medinet, a Canadian healthcare tech provider. This could have exposed anything from patient portals to provider dashboards. Healthcare + SSL issues = serious HIPAA and trust nightmares.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-help-gurusoft-com-sg\">help.gurusoft.com.sg<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The support subdomain of GuruSoft, a supply-chain software firm in Singapore. A compromised support portal? That\u2019s a perfect place for phishing attacks or <a href=\"https:\/\/certera.com\/blog\/what-is-social-engineering-techniques-examples-best-practices-preventions\/\">social engineering campaigns<\/a> on their clients.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-banners-betvictor-com\">banners.betvictor.com<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A subdomain for BetVictor, a major gambling and betting site. This domain serves ad banners, which means attackers could have used it to inject malware into ad networks, infecting users across the web.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-can-revoking-ssl-certificates-help\">Can Revoking SSL Certificates Help?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Yes, revoking a bad SSL certificate helps \u2014 but it\u2019s not a silver bullet. When a certificate is revoked, it\u2019s added to a special list (called a <a href=\"https:\/\/certera.com\/blog\/ocsp-vs-crl-know-the-difference\/\">CRL<\/a>) or flagged through something called <a href=\"https:\/\/certera.com\/blog\/what-is-ocsp-stapling-or-ssl-stapling-a-detailed-guide\/\">OCSP<\/a>. This tells browsers, \u201cHey, don\u2019t trust this certificate anymore.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sounds solid, right? Here&#8217;s the catch. Revocation only works if browsers and servers are checking that list, and not all of them do. That\u2019s why relying only on certificate revocation isn\u2019t enough. Combine revocation with regular monitoring, certificate audits, and smart security strategies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-s-the-big-lesson-here\">What\u2019s the Big Lesson Here?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Just because someone receives an email doesn\u2019t mean they own the domain. Validation logic needs to be bulletproof, especially when trusted by every major browser on the planet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This wasn\u2019t just a small slip-up. If left unchecked, it could\u2019ve let attackers impersonate big brands, run <a href=\"https:\/\/certera.com\/blog\/phishing-attacks-explained-how-to-spot-and-prevent-online-scams\/\">phishing attacks<\/a>, or snoop on encrypted traffic. Don\u2019t blindly trust certificate authorities. Monitor your domains, use <a href=\"https:\/\/certera.com\/ssl-tools\/caa-record-generator\">CAA records<\/a>, and watch Certificate Transparency logs.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conclusion\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">SSL certificates are crucial for online security, but vulnerabilities like the one at SSL.com remind us that even trusted systems can fail. While the issue has been fixed, it highlights the need for proactive security measures. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stay ahead of potential threats with our new <a href=\"https:\/\/certera.com\/sitelock\">SiteLock monitoring tools<\/a> designed to detect errors and vulnerabilities before they affect you.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-want-to-stay-secure\">Want to Stay Secure?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Reach out to us and explore <a href=\"https:\/\/certera.com\/\">Certera &#8211; Modern Certificate Authority<\/a> can help protect your domains, code, emails, and entire web presence today!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A critical vulnerability in the SSL.com domain validation process allowed unauthorized parties to get the certificates on behalf of you or your organisation. SSL.com is one of the famous Certificate Authorities (CA) trusted by all major browsers. This Vulnerability is reported by security researchers; in their demonstration, they showed how an attacker can misuse it<span class=\"morelink d-block mt-3\"><a href=\"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/\">Read More<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":3488,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,32],"tags":[671,672],"class_list":["post-3485","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ssl-certificate","category-vulnerability","tag-ssl-com-vulnerability","tag-ssl-coms-domain-validation-process","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.6 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SSL.com Vulnerability Issued Unauthorized SSL Certificates<\/title>\n<meta name=\"description\" content=\"SSL.com&#039;s domain validation system had an unfortunate bug that allows unauthorized users to obtain certificates for Alibaba Cloud&#039;s domain.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Unauthorized Certificates Issued for Alibaba Cloud Due to SSL.com CA Flaw\" \/>\n<meta property=\"og:description\" content=\"SSL.com&#039;s domain validation system had an unfortunate bug that allows unauthorized users to obtain certificates for Alibaba Cloud&#039;s domain.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/\" \/>\n<meta property=\"og:site_name\" content=\"EncryptedFence by Certera - Web &amp; Cyber Security Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/certeraLLC\/\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-25T11:50:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-26T11:22:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/04\/ssl-dot-com-dcv-bug.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"620\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:site\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/\"},\"author\":{\"name\":\"Janki Mehta\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\"},\"headline\":\"Unauthorized Certificates Issued for Alibaba Cloud Due to SSL.com CA Flaw\",\"datePublished\":\"2025-04-25T11:50:52+00:00\",\"dateModified\":\"2025-05-26T11:22:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/\"},\"wordCount\":881,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/ssl-dot-com-dcv-bug.webp\",\"keywords\":[\"SSL.com Vulnerability\",\"SSL.com's domain validation process\"],\"articleSection\":[\"SSL Certificate\",\"Vulnerability\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/#respond\"]}],\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/\",\"name\":\"SSL.com Vulnerability Issued Unauthorized SSL Certificates\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/ssl-dot-com-dcv-bug.webp\",\"datePublished\":\"2025-04-25T11:50:52+00:00\",\"dateModified\":\"2025-05-26T11:22:42+00:00\",\"description\":\"SSL.com's domain validation system had an unfortunate bug that allows unauthorized users to obtain certificates for Alibaba Cloud's domain.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/#primaryimage\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/ssl-dot-com-dcv-bug.webp\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/ssl-dot-com-dcv-bug.webp\",\"width\":960,\"height\":620,\"caption\":\"SSL.com Critical Vulnerability\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/certera.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Unauthorized Certificates Issued for Alibaba Cloud Due to SSL.com CA Flaw\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"name\":\"EncryptedFence by Certera - Web & Cyber Security Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"alternateName\":\"Certera's EncryptedFence Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/certera.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\",\"name\":\"Certera\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"caption\":\"Certera\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/certeraLLC\\\/\",\"https:\\\/\\\/x.com\\\/certera_llc\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/certera-llc\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\",\"name\":\"Janki Mehta\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"caption\":\"Janki Mehta\"},\"description\":\"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\\\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.\",\"sameAs\":[\"https:\\\/\\\/certerassl.com\\\/\"],\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/author\\\/certerabguser\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SSL.com Vulnerability Issued Unauthorized SSL Certificates","description":"SSL.com's domain validation system had an unfortunate bug that allows unauthorized users to obtain certificates for Alibaba Cloud's domain.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/","og_locale":"en_US","og_type":"article","og_title":"Unauthorized Certificates Issued for Alibaba Cloud Due to SSL.com CA Flaw","og_description":"SSL.com's domain validation system had an unfortunate bug that allows unauthorized users to obtain certificates for Alibaba Cloud's domain.","og_url":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/","og_site_name":"EncryptedFence by Certera - Web &amp; Cyber Security Blog","article_publisher":"https:\/\/www.facebook.com\/certeraLLC\/","article_published_time":"2025-04-25T11:50:52+00:00","article_modified_time":"2025-05-26T11:22:42+00:00","og_image":[{"width":960,"height":620,"url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/04\/ssl-dot-com-dcv-bug.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_creator":"@certera_llc","twitter_site":"@certera_llc","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/#article","isPartOf":{"@id":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/"},"author":{"name":"Janki Mehta","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7"},"headline":"Unauthorized Certificates Issued for Alibaba Cloud Due to SSL.com CA Flaw","datePublished":"2025-04-25T11:50:52+00:00","dateModified":"2025-05-26T11:22:42+00:00","mainEntityOfPage":{"@id":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/"},"wordCount":881,"commentCount":0,"publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"image":{"@id":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/04\/ssl-dot-com-dcv-bug.webp","keywords":["SSL.com Vulnerability","SSL.com's domain validation process"],"articleSection":["SSL Certificate","Vulnerability"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/#respond"]}],"copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/certera.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/","url":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/","name":"SSL.com Vulnerability Issued Unauthorized SSL Certificates","isPartOf":{"@id":"https:\/\/certera.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/#primaryimage"},"image":{"@id":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/04\/ssl-dot-com-dcv-bug.webp","datePublished":"2025-04-25T11:50:52+00:00","dateModified":"2025-05-26T11:22:42+00:00","description":"SSL.com's domain validation system had an unfortunate bug that allows unauthorized users to obtain certificates for Alibaba Cloud's domain.","breadcrumb":{"@id":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/#primaryimage","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/04\/ssl-dot-com-dcv-bug.webp","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/04\/ssl-dot-com-dcv-bug.webp","width":960,"height":620,"caption":"SSL.com Critical Vulnerability"},{"@type":"BreadcrumbList","@id":"https:\/\/certera.com\/blog\/unauthorized-certificates-issued-for-alibaba-cloud-due-to-ssl-com-ca-flaw\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/certera.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Unauthorized Certificates Issued for Alibaba Cloud Due to SSL.com CA Flaw"}]},{"@type":"WebSite","@id":"https:\/\/certera.com\/blog\/#website","url":"https:\/\/certera.com\/blog\/","name":"EncryptedFence by Certera - Web & Cyber Security Blog","description":"","publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"alternateName":"Certera's EncryptedFence Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/certera.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/certera.com\/blog\/#organization","name":"Certera","url":"https:\/\/certera.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","caption":"Certera"},"image":{"@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/certeraLLC\/","https:\/\/x.com\/certera_llc","https:\/\/www.linkedin.com\/company\/certera-llc\/"]},{"@type":"Person","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7","name":"Janki Mehta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","caption":"Janki Mehta"},"description":"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.","sameAs":["https:\/\/certerassl.com\/"],"url":"https:\/\/certera.com\/blog\/author\/certerabguser\/"}]}},"_links":{"self":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3485","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/comments?post=3485"}],"version-history":[{"count":3,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3485\/revisions"}],"predecessor-version":[{"id":3611,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3485\/revisions\/3611"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media\/3488"}],"wp:attachment":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media?parent=3485"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/categories?post=3485"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/tags?post=3485"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}