StartCom: public exponent is 1
This case reports that a certificate for https://secure-1.lukegb.com had an RSA public exponent value of 1. The reporter cited section 6.1.6 of version 1.3 of the CA/Browser Forum Baseline Requirements, which requires the public exponent to be an odd number equal to 3 or more. A Mozilla participant noted that even though Firefox rejects the certificate, it was not in compliance with the Baseline Requirements. StartCom stated that they would revoke the certificate and would check for additional certificates with similar issues, and that they would verify their CSR submission checks detect an exponent lower than 3. The bug was later resolved with the resolution set to WONTFIX, and a Mozilla comment indicated that if StartCom became trusted again, they were unlikely to have the same issues.
- A CA Program bug was filed regarding a StartCom certificate with RSA public exponent set to 1.
- StartCom stated it would revoke the affected certificate and review for additional occurrences.
- Mozilla resolved the bug.
- Mozilla representative — Reported that the certificate for https://secure-1.lukegb.com had public exponent 1 and referenced the Baseline Requirements requirement that the exponent be an odd number equal to 3 or more.
- Mozilla representative — Noted that although Firefox rejects the certificate, it is not compliant with the Baseline Requirements.
- Ipv representative — Created an attachment (e1.pem).
- Startcom representative — Said StartCom is revoking the certificate, will check for more, and will verify CSR submission checks detect an exponent lower than 3.
- Mozilla representative — Resolved the bug, stating that if StartCom becomes trusted again, they are unlikely to have the same issues.