← Start Commercial (StartCom) Ltd. cases
Bugzilla #1212655 Certificate Misissuance

StartCom: public exponent is 1

RESOLVED WONTFIX Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports that a certificate for https://secure-1.lukegb.com had an RSA public exponent value of 1. The reporter cited section 6.1.6 of version 1.3 of the CA/Browser Forum Baseline Requirements, which requires the public exponent to be an odd number equal to 3 or more. A Mozilla participant noted that even though Firefox rejects the certificate, it was not in compliance with the Baseline Requirements. StartCom stated that they would revoke the certificate and would check for additional certificates with similar issues, and that they would verify their CSR submission checks detect an exponent lower than 3. The bug was later resolved with the resolution set to WONTFIX, and a Mozilla comment indicated that if StartCom became trusted again, they were unlikely to have the same issues.

Model: gpt-5.4-nano Generated: 2026-06-13 14:01 UTC Revised: 2026-06-16 18:42 UTC Confidence: 0.86 5 comments
Chronology
  1. A CA Program bug was filed regarding a StartCom certificate with RSA public exponent set to 1.
  2. StartCom stated it would revoke the affected certificate and review for additional occurrences.
  3. Mozilla resolved the bug.
Thread Activity
  1. Mozilla representative — Reported that the certificate for https://secure-1.lukegb.com had public exponent 1 and referenced the Baseline Requirements requirement that the exponent be an odd number equal to 3 or more.
  2. Mozilla representative — Noted that although Firefox rejects the certificate, it is not compliant with the Baseline Requirements.
  3. Ipv representative — Created an attachment (e1.pem).
  4. Startcom representative — Said StartCom is revoking the certificate, will check for more, and will verify CSR submission checks detect an exponent lower than 3.
  5. Mozilla representative — Resolved the bug, stating that if StartCom becomes trusted again, they are unlikely to have the same issues.
Participants
Mozilla representative Startcom representative Ipv representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1409760 RESOLVED Certificate Misissuance Opened 2017-10-18 · Closed 2022-11-14 · 67% similar
StartCom: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1015767 RESOLVED Certificate Misissuance Opened 2014-05-25 · Closed 2022-11-14 · 59% similar
startcom: still issuing < 2048 bit certificates
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 59% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1386894 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-03 · Closed 2023-02-22 · 58% similar
StartCom: Non-BR-Compliant Certificate Issuance -- adding Certnomis intermediates to OneCRL
#1398243 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 55% similar
certSIGN: Non-BR-Compliant OCSP Responders
#1293366 RESOLVED Certificate Misissuance Opened 2016-08-08 · Closed 2022-11-14 · 54% similar
WoSign issued SHA-1 SSL certs and backdated the issuance date on SSL certificates
#1269183 RESOLVED Certificate Misissuance Opened 2016-05-01 · Closed 2022-11-14 · 53% similar
StartCom: Certificates using secp256k1
#1391867 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-19 · Closed 2023-02-22 · 47% similar
Let's Encrypt: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action