I don't think this is the bug per se, but it may very well be due to their reaction to the bug. The safe response for secure systems is to reissue certs after patching impacted OpenSSL instances. It looks like they instead have switched over to a previously-issued wildcard cert for *.stackexchange.com. The cert is valid, but it's for the wrong domain. This is more likely the result of a sysadmin screwing up the respo…
We hope to get the final cert deployed within the hour...as soon as we have it in hand. Our other certs are queued up and ready to do on a secondary load balancer.
CAs are understandably a bit busier than normal today.