← WoSign CA Limited cases
Bugzilla #1293366 Certificate Misissuance

WoSign issued SHA-1 SSL certificates and backdated issuance dates via an API parameter

RESOLVED FIXED WoSign CA Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns WoSign CA Limited issuing SSL certificates that used SHA-1 and had backdated issuance dates. The issue was reported after Christiaan Ottow noted that a StartEncrypt API parameter (caID) could be used to select a CA, and that a test certificate obtained via this API was dated December 20, 2015 and signed using SHA-1. Kathleen Wilson asked WoSign to explain when it was notified, what analysis it performed to identify the affected certificates, and what remediation would be taken. WoSign (Richard) stated it received a report from Computest before Computest publicly disclosed the bug, then checked that only Computest used the bug and deleted the “discard API parameter,” and asked StartCom to stop using the API. WoSign provided details showing two test certificates with issuance times in June 2016 but “not before” dates in December 2015, and stated it revoked the two certificates and did not think they needed to be added to OneCRL. WoSign also described steps to prevent future misissuance, including logging issued SSL certificates to Google and other log servers and advising browsers to distrust WoSign SSL certificates issued after July 5, 2016 that do not include SCT data. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 14:04 UTC Revised: 2026-06-16 18:11 UTC Confidence: 0.86 9 comments
Chronology
  1. Two test SSL certificates were issued with issuance times in June 2016 but “not before” dates in December 2015.
  2. A second test SSL certificate was issued with issuance time in June 2016 but “not before” date in December 2015.
  3. A report about the StartEncrypt API behavior and the resulting backdated SHA-1 certificates was posted to the mozilla.dev.security.policy forum.
  4. A Mozilla CA Program bug was filed regarding WoSign’s SHA-1 and backdated SSL certificate issuance.
  5. WoSign responded with analysis, identified two affected test certificates, and described remediation steps including deleting the API parameter and stopping the API.
Thread Activity
  1. Mozilla representative — Reported that WoSign-issued SSL certificates were backdated and SHA-1, based on a StartEncrypt API caID parameter selecting WoSign, and attached the affected certificate details.
  2. Mozilla representative — Asked WoSign to answer questions about notification/containment timing, analysis of which SHA-1/backdated certificates were issued, which certificates should be added to OneCRL, and the remediation timeline.
  3. WoSign CA Limited — Provided an attachment containing two mis-issued certificates.
  4. WoSign CA Limited — Stated WoSign received a report from Computest before Computest publicized the bug, deleted the discard API parameter, asked StartCom to stop using the API, and identified two test certificates as the only ones issued in this way.
  5. WoSign CA Limited — Described prevention steps, including logging issued SSL certificates to Google and other log servers and guidance for browsers/customers regarding SCT data.
  6. Mozilla representative — Reposted the WoSign response details including certificate issuance and “not before” dates and certificate attributes.
  7. Community commenter — Commented that users couldn’t mark a WoSign certificate as untrusted without untrusting the whole StartSSL CA.
  8. Mozilla representative — Added a link to additional problems with WoSign SSL certificate issuance process/code.
  9. Mozilla representative — Noted that Mozilla has taken action regarding WoSign and referenced a policy forum message.
Participants
Mozilla representative WoSign CA Limited Community commenter
Similar Local Cases
#1398243 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 76% similar
certSIGN: Non-BR-Compliant OCSP Responders
#1649942 RESOLVED Certificate Misissuance Opened 2020-07-02 · Closed 2023-02-22 · 69% similar
SK ID Solutions: Incorrect OCSP Delegated Responder Certificate
#1391867 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-19 · Closed 2023-02-22 · 67% similar
Let's Encrypt: Non-BR-Compliant Certificate Issuance
#1409760 RESOLVED Certificate Misissuance Opened 2017-10-18 · Closed 2022-11-14 · 67% similar
StartCom: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1524730 RESOLVED Certificate Misissuance Revocation Issue Opened 2019-02-02 · Closed 2023-02-22 · 62% similar
Sectigo: invalid dnsName
#1654896 RESOLVED Certificate Misissuance Opened 2020-07-23 · Closed 2023-02-22 · 62% similar
GlobalSign: Certificates with RSA keys where modulus is not divisible by 8
#1743935 RESOLVED Certificate Misissuance Incident Opened 2021-12-02 · Closed 2023-02-22 · 62% similar
Amazon Trust Services: Misissuance of Subordinate Per CPS
#1390977 RESOLVED Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 62% similar
Camerfirma: Non-BR-Compliant Certificate Issuance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action