startcom: still issuing < 2048 bit certificates
The bug was opened after Kurt Roeckx reported that StartCom had issued a certificate with a key size below the required 2048 bits. In the initial report, Kurt said he found a 2043-bit certificate generated by StartCom and attached the certificate to the bug. Eddy Nigg (StartCom) asked Kurt to attach the certificate and later said they would look into it closely. Mozilla asked for an update on what happened before closing, noting the issue appeared low risk from a security perspective. Eddy said he could reproduce the behavior with a particular request but did not have an explanation for why it reported 2048 bits instead of 2043, and he had not found another similar example. Mozilla resolved the bug as WORKSFORME, with a note that any UI would use the magic number 2048 rather than 2043. Later comments from Kurt indicated he continued to see certificates with key sizes below 2048 bits, including a 2046-bit key in December 2014 and an example referenced via crt.sh in 2015.
- Kurt Roeckx reported finding a StartCom-issued certificate with a 2043-bit key size (below the 2048-bit requirement) and opened the bug.
- Kurt attached the reported 2043-bit certificate to the bug after StartCom requested the attachment.
- StartCom acknowledged the report and said they would look into it closely.
- Mozilla requested an explanation/update; StartCom stated it could reproduce the issue but did not have an explanation and noted it could be taken offline if necessary.
- Mozilla resolved the bug as WORKSFORME, citing low risk and warning about using 2048 rather than 2043 in any UI.
- Kurt reported seeing a 2046-bit key from December 2014.
- Kurt reported additional examples in 2015 and linked to a crt.sh entry.
- Roeckx representative — Reported finding a StartCom certificate generated in the prior month with a 2043-bit key size (below 2048 bits) and said it was not a big security problem.
- Startcom representative — Asked Kurt to attach the certificate he found to the bug.
- Roeckx representative — Attached the 2043-bit certificate (2043bit.pem).
- Startcom representative — Acknowledged the issue and said it shouldn't happen and they would look into it closely.
- Mozilla representative — Asked Eddy for news on what happened before closing, agreeing it was low risk but wanting an explanation.
- Startcom representative — Said he could reproduce the behavior with a particular request but had no explanation; noted the code is based on a popular library and reports 2048 bits instead of 2043, and that he hadn’t found another example.
- Mozilla representative — Resolved the bug as low risk (WORKSFORME) and warned that any UI should use 2048 rather than 2043.
- Startcom representative — Agreed that they do not want any <2048-bit certificates in use.
- Roeckx representative — Reported still seeing a 2046-bit key from December 2014.
- Roeckx representative — Reported seeing other examples in 2015 and linked to a crt.sh entry.