Skip to main content

Tagged “mass-revocation”

← All posts

incidents TLS Radar Team 6 min read

SSL.com Revoked 2,700 Certificates in 24 Hours After an Audit Found a Missing Check

An annual WebTrust audit found four sampled certificates with no evidence that multi-perspective domain validation was performed. The full investigation found 2,700, and SSL.com revoked them all within a day. What MPIC is, why you could not have seen this one coming, the second SSL.com incident you can check for yourself, and what TLS Radar's new revocation checking does about it.

strategy TLS Radar Team 4 min read

What Two Weeks of CA Compliance Incidents Say About Your Revocation Risk

In the two weeks ending August 27, 2026, more than 30 public CAs logged 69 compliance incidents in Mozilla's tracker - delayed revocations, country-field and clientAuth misissuance, and the process failures that precede distrust. Every incident sourced to its Bugzilla bug, grouped by what it means for the certificates your business depends on.

strategy TLS Radar Team 5 min read

The Let's Encrypt Mass Revocation Simulation Was a Warning to Every TLS Customer

On March 19, 2026, Let's Encrypt simulated a 3 million cert mass revocation. Two weeks later, another CA revoked 1.7 million real certificates in 24 hours. Both events told the same story: your CA can revoke your cert for reasons you don't control, and most renewal automation won't respond in time.

strategy TLS Radar Team 9 min read

NET::ERR_CERT_AUTHORITY_INVALID in Chrome and Brave: The Real Causes in 2026

Two reasons Chrome and Brave throw NET::ERR_CERT_AUTHORITY_INVALID: distrusted legacy roots (SSL.com 2016, DigiCert G1, Entrust) - the live, current cause - and CA-side compliance revocations, illustrated by a mid-sized CA's forced revocation of 63,525 certificates in July 2026. CA-agnostic diagnostics and fix steps.

Subscribe via RSS.