StartCom: Certificates using secp256k1
The case concerns StartCom certificates that use the secp256k1 elliptic curve. The initial report noted that certificates such as https://crt.sh/?id=17662860 use secp256k1, which is not one of the three allowed curves by the BR. StartCom responded that it had only recently started to support elliptic curves and that it would allow only the currently permitted signatures. StartCom stated that remaining certificates with non-compliant curves would be replaced and revoked. Mozilla resolved the bug with a WONTFIX resolution, and noted that if StartCom became trusted again, it was unlikely to have the same issues. The bug is currently marked RESOLVED.
- A report was raised about StartCom certificates using the secp256k1 curve.
- StartCom stated it would replace and revoke remaining certificates with non-compliant curves.
- Mozilla resolved the case with WONTFIX.
- Roeckx representative — Reported that certificates (e.g., https://crt.sh/?id=17662860) use secp256k1, which is not among the three allowed curves by the BR.
- Community commenter — Said StartCom had only recently started supporting elliptic curves, would allow only currently permitted signatures, and would replace and revoke remaining non-compliant certificates.
- Mozilla representative — Resolved the bug, stating that if StartCom became trusted again, it was unlikely to have the same issues.