← Start Commercial (StartCom) Ltd. cases
Bugzilla #1024143
Self Reported Incident
Disclosure of StartCom CA Certificates
RESOLVED
WORKSFORME
Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case is a disclosure by StartCom regarding its CA certificates. The reporter states that all StartCom CA certificates are permanently disclosed at https://www.startssl.com/certs/. They further explain that the certificates are either strictly controlled by StartCom or covered by a current WebTrust audit by the CA controlling the key material that was signed by StartCom. No additional compliance incident, misissuance event, or revocation issue is described in the thread. The bug is marked as RESOLVED with resolution WORKSFORME.
Chronology
- StartCom submitted a disclosure statement about its CA certificates and where they are permanently published.
Thread Activity
- Community commenter — Eddy Nigg stated that all StartCom CA certificates are permanently disclosed at https://www.startssl.com/certs/ and are either strictly controlled by StartCom or covered by a current WebTrust audit by the CA controlling the key material.
Participants
Community commenter
External References
Similar Local Cases
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB
Clarification requested regarding remediation of StartCom certificate issuance vulnerability
Camerfirma: Startcom are issuing by proxy using Camerfirma
StartCom: OCSP responder often returns "unknown" for recently-issued certificates
StartCom: Action Items
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
GoDaddy: Action Items
Actalis: Certs issued with same issuer and serial number