StartCom: IV without localityName or stateOrProvinceName
This case concerns StartCom certificates that were described as individual-validated (IV) but lacked either the localityName or stateOrProvinceName fields. The issue was raised because the CA/B Forum Baseline Requirements require that either localityName or stateOrProvinceName be present. StartCom reported that it found six IV certificates with a similar problem and said it would offer replacements to subscribers and revoke the non-compliant certificates. StartCom also noted that additional verification steps might be needed to confirm the locality and that its verification teams had been updated. Mozilla resolved the bug with a WONTFIX resolution, stating that if StartCom became trusted again, it was unlikely to have the same issues. The bug is currently marked RESOLVED.
- A report was filed about StartCom IV certificates missing localityName and/or stateOrProvinceName.
- StartCom began investigating the reported non-compliance.
- StartCom identified six affected IV certificates and planned subscriber replacements and revocations.
- Mozilla resolved the bug as WONTFIX.
- Roeckx representative — Reported that an individual-validated certificate lacked localityName or stateOrProvinceName and cited the BR requirement for one of those fields.
- Startcom representative — Said StartCom was looking into the issue right away.
- Startcom representative — Stated StartCom found six similar IV certificates, would offer replacements and revoke non-compliant certificates, and that additional verification might be needed; said verification teams were updated.
- Mozilla representative — Resolved the bug with WONTFIX, noting that if StartCom became trusted again it was unlikely to have the same issues.