← WoSign CA Limited cases
Bugzilla #1293366 Certificate Misissuance

WoSign issued SHA-1 SSL certs and backdated the issuance date on SSL certificates

RESOLVED WoSign CA Limited
AI Summary

WoSign CA Limited was found to have issued SHA-1 SSL certificates with backdated issuance dates. This issue was reported by Christiaan Ottow and raised concerns about the potential misuse of a non-public API that allowed backdated certificate issuance. WoSign responded by revoking the affected certificates and implementing measures to prevent future mis-issuance, including logging all issued certificates to public CT logs.

Model: gpt-4o-mini Generated: 2026-06-13 14:04 UTC Confidence: 0.95
Chronology
  1. Issue reported by Christiaan Ottow
  2. Bug filed and initial responses from WoSign
  3. WoSign confirmed the mis-issuance and provided details
  4. Further discussions on the implications and actions taken
  5. Mozilla took action regarding WoSign
Participants
Kathleen Wilson Richard Wang Christiaan Ottow Filip Jirsak Gervase Markham
Similar Local Cases
#1414039 RESOLVED Certificate Misissuance Opened 2017-11-02 · Closed 2024-05-09 · 59% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1404403 RESOLVED Certificate Misissuance Opened 2017-09-29 · Closed 2023-02-22 · 57% similar
SwissSign: Two certs issued with same issuer and serial number
#1391056 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 57% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1315016 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 57% similar
SHA-1 issuance by Visa root
#1283498 RESOLVED Certificate Misissuance Opened 2016-06-30 · Closed 2022-11-14 · 57% similar
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
#1405817 RESOLVED Certificate Misissuance Opened 2017-10-04 · Closed 2023-02-22 · 56% similar
Actalis: Certs issued with same issuer and serial number
#1313873 RESOLVED Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 56% similar
SHA-1 issuance by DocuSign root
#1405815 RESOLVED Certificate Misissuance Opened 2017-10-04 · Closed 2023-02-22 · 55% similar
Camerfirma: Certs issued with same issuer and serial number

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action