← Start Commercial (StartCom) Ltd. cases
Bugzilla #1015767 Certificate Misissuance

startcom: still issuing < 2048 bit certificates

RESOLVED WORKSFORME Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened after Kurt Roeckx reported that StartCom had issued a certificate with a key size below the required 2048 bits. In the initial report, Kurt said he found a 2043-bit certificate generated by StartCom and attached the certificate to the bug. Eddy Nigg (StartCom) asked Kurt to attach the certificate and later said they would look into it closely. Mozilla asked for an update on what happened before closing, noting the issue appeared low risk from a security perspective. Eddy said he could reproduce the behavior with a particular request but did not have an explanation for why it reported 2048 bits instead of 2043, and he had not found another similar example. Mozilla resolved the bug as WORKSFORME, with a note that any UI would use the magic number 2048 rather than 2043. Later comments from Kurt indicated he continued to see certificates with key sizes below 2048 bits, including a 2046-bit key in December 2014 and an example referenced via crt.sh in 2015.

Model: gpt-5.4-nano Generated: 2026-06-13 13:55 UTC Revised: 2026-06-16 18:40 UTC Confidence: 0.74 10 comments
Chronology
  1. Kurt Roeckx reported finding a StartCom-issued certificate with a 2043-bit key size (below the 2048-bit requirement) and opened the bug.
  2. Kurt attached the reported 2043-bit certificate to the bug after StartCom requested the attachment.
  3. StartCom acknowledged the report and said they would look into it closely.
  4. Mozilla requested an explanation/update; StartCom stated it could reproduce the issue but did not have an explanation and noted it could be taken offline if necessary.
  5. Mozilla resolved the bug as WORKSFORME, citing low risk and warning about using 2048 rather than 2043 in any UI.
  6. Kurt reported seeing a 2046-bit key from December 2014.
  7. Kurt reported additional examples in 2015 and linked to a crt.sh entry.
Thread Activity
  1. Roeckx representative — Reported finding a StartCom certificate generated in the prior month with a 2043-bit key size (below 2048 bits) and said it was not a big security problem.
  2. Startcom representative — Asked Kurt to attach the certificate he found to the bug.
  3. Roeckx representative — Attached the 2043-bit certificate (2043bit.pem).
  4. Startcom representative — Acknowledged the issue and said it shouldn't happen and they would look into it closely.
  5. Mozilla representative — Asked Eddy for news on what happened before closing, agreeing it was low risk but wanting an explanation.
  6. Startcom representative — Said he could reproduce the behavior with a particular request but had no explanation; noted the code is based on a popular library and reports 2048 bits instead of 2043, and that he hadn’t found another example.
  7. Mozilla representative — Resolved the bug as low risk (WORKSFORME) and warned that any UI should use 2048 rather than 2043.
  8. Startcom representative — Agreed that they do not want any <2048-bit certificates in use.
  9. Roeckx representative — Reported still seeing a 2046-bit key from December 2014.
  10. Roeckx representative — Reported seeing other examples in 2015 and linked to a crt.sh entry.
Participants
Roeckx representative Startcom representative Mozilla representative
External References
Similar Local Cases
#1269183 RESOLVED Certificate Misissuance Opened 2016-05-01 · Closed 2022-11-14 · 92% similar
StartCom: Certificates using secp256k1
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 68% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1315018 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 67% similar
SHA-1 issuance by GlobalSign root
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 67% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1398428 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 67% similar
Amazon Trust Services: CAA Misissuances
#682956 RESOLVED Certificate Misissuance Opened 2011-08-29 · Closed 2022-11-14 · 66% similar
Investigate *.google.com certificate issued by DigiNotar and used by Iran government?
#1420871 RESOLVED Certificate Misissuance Opened 2017-11-27 · Closed 2023-02-22 · 66% similar
Camerfirma: Potential Mis-Issuance based on CAA records
#1625421 RESOLVED Certificate Misissuance Opened 2020-03-27 · Closed 2024-05-09 · 61% similar
FNMT: QC Statement that contains at least one of the ETSI ESI statements

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action