Blog Article

MPIC in Practice: What the SSL.com Revocation Event Shows About the Modern WebPKI

October 6, 2026
4 min read
Expert Content

Published on

October 6, 2026

On September 10, 2026, SSL.com published a compliance update announcing the revocation of a subset of its TLS certificates, about 2,700 across DV, OV and EV types, completed within the short window the industry rules require. The cause was neither a breach nor a mississuance. An internal audit found that for these certificates, the company could not evidence that domain control had been corroborated from multiple network perspectives, a requirement in force since March 2025. Primary domain validation had been performed, and SSL.com reports no indication of compromise or of incorrect validation. The certificates were revoked because the WebPKI holds certificate authorities to a demanding standard: validation needs to be provable, certificate by certificate, not merely performed.

It is worth saying clearly at the outset that SSL.com handled this the way the system intends. The company identified the gap through its own audit, disclosed it publicly, notified affected subscribers, and completed the revocation on schedule. This is the WebPKI's compliance model functioning, and the event is interesting not as a story about one CA, but as a window into how modern public trust works and what it asks of everyone who relies on it.

What MPIC Is, and Why the Rule Exists

Multi-Perspective Issuance Corroboration (MPIC) entered the CA/Browser Forum's Baseline Requirements through Ballot SC-067, adopted in August 2024 and enforced since March 15, 2025. The threat it answers is well documented: when a certificate authority checks that an applicant controls a domain, an attacker positioned on the network path, typically through BGP manipulation, can intercept that check from a single vantage point and pass it fraudulently. MPIC closes that door by requiring the CA to corroborate domain control from multiple network perspectives in different regions, with a quorum that rises on a published calendar: three perspectives since March 2026, four since June, five from December.

MPIC is one of the quiet structural upgrades that keep public trust robust, and this event is an early illustration of how seriously it is enforced. The requirement covers not only performing the corroboration but retaining the evidence of it. When that evidence could not be confirmed, the conservative path was the correct one, and it is the path SSL.com took.

The Part That Concerns Everyone Else

The operational lesson of the event sits downstream of the CA, and it applies to every organization that consumes publicly trusted certificates, from any provider.

Take control of your PKI infrastructure

See how Evertrust simplifies certificate lifecycle management.

Get Started

The Baseline Requirements leave certificate authorities very little discretion on revocation timelines, by design. Browsers and root programs hold every CA to the same clock, because consistency is what keeps the trust model credible. The practical consequence is that when a compliance finding occurs anywhere in the chain, subscribers receive a replacement notice with a deadline measured in hours or days, regardless of how carefully they run their own operations. The trigger sits entirely outside the subscriber's control.

Want to master certificate management?

Browse our resources on PKI best practices.

Education Center

This is why replacement events of this kind are best understood as a normal, recurring feature of the WebPKI rather than an exception. The ecosystem has seen several in recent years, affecting customers of different CAs for different reasons, and the pattern is structural: strict rules, strictly enforced, with short timelines absorbed downstream. Organizations with a complete certificate inventory and automated replacement in place, through ACME or equivalent protocols, handle such an event routinely: affected certificates are reissued and redeployed quickly, with little manual effort. For organizations still handling replacement manually, these events are a useful prompt to assess how long a short-notice replacement would take across their estate, and whether the deployment locations of every certificate are known. That assessment is far more comfortable to run on a quiet day than during an actual event.

The direction of travel reinforces the point. Certificate lifetimes are on a published path toward 47 days in 2029, domain validation reuse windows are shrinking in parallel, and the MPIC quorum rises again in December. Each of these changes increases the number of certificate events an organization handles per year, and each assumes that the subscriber side keeps pace. Replacement readiness is becoming a standing capability of certificate operations rather than an exceptional procedure.

Closing Thoughts

The September 10 event ends with the system in a healthier state than it began: a validation evidence gap found and closed, affected certificates replaced, and a requirement reaffirmed that protects every relying party on the Internet. For certificate owners, the takeaway is neither alarm nor blame. It is a planning assumption: in the modern WebPKI, short-notice replacement is part of the operating environment, whichever CA you work with, and the organizations that fare best are the ones that have made it routine.

Was this helpful?
Back to blog

Table of Contents

Stay Updated

Get the latest PKI insights delivered to your inbox.

By subscribing you accept to receive our communications. You can unsubscribe at any moment.

Related Articles

Evertrust PQC

Are European enterprises ready for Post-Quantum Cryptography (PQC) migration? The gaps and the path forward

September 10, 2025
1 min

Explore why PQC adoption lags in Europe, the real blockers, and how to achieve quantum-safe security.

Read more
Evertrust PQC

NIST Releases New Post-Quantum Cryptography Standards

September 10, 2025
1 min

Discover NIST’s new Post-Quantum Cryptography standards (FIPS 203, 204, 205) and how Evertrust is preparing to integrate them for enhanced cybersecurity.

Read more
Evertrust ACME

ACME Clients on Linux

February 12, 2024
1 min

The ACME protocol is a network protocol designed to automate the process of domain validation, deliverance and renewal of X.509 certificates. The process is set up between an ACME server and an ACME client.

Read more
Get started

Ready to take back control over your certificates?

Talk to our experts and discover how Evertrust can help you implement best practices in PKI and certificate lifecycle management.