← WoSign CA Limited cases
Bugzilla #1311824 Self Reported Incident

WoSign: Action Items

RESOLVED INCOMPLETE WoSign CA Limited
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves WoSign CA Limited's proactive disclosure of compliance failures related to their root certificates. Following a prior bug report, WoSign was informed that new certificates issued after October 21, 2016, would not be trusted in Mozilla products. The CA outlined a series of action items to rectify these issues, including implementing changes to their processes and obtaining external audits. As of the last update, WoSign had completed a security audit by Cure53 and was preparing for further compliance audits. The case is currently resolved but remains under monitoring for WoSign's future compliance.

Model: gpt-4o-mini Generated: 2026-06-13 14:06 UTC Revised: 2026-06-16 18:11 UTC Confidence: 0.85 13 comments
Chronology
  1. WoSign CA Limited disclosed compliance failures and outlined action items for future trust.
  2. Requirements communicated to WoSign; case deemed not actionable until reapplication for inclusion.
  3. WoSign completed a security audit and submitted the report to Mozilla.
Thread Activity
  1. Mozilla representative — Outlined the conditions under which WoSign could regain trust in Mozilla products.
  2. Assecods representative — Reported on the revocation of subordinate CAs issued to Certification Authority of WoSign G2.
  3. Mozilla representative — Confirmed that the requirements have been communicated to WoSign.
  4. WoSign CA Limited — Submitted the security audit report summary to Mozilla.
Participants
Mozilla representative Assecods representative WoSign CA Limited
External References
Similar Local Cases
#1311832 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2016-10-20 · Closed 2023-01-27 · 81% similar
StartCom: Action Items
#1315016 RESOLVED Self Reported Incident Opened 2016-11-03 · Closed 2022-11-14 · 76% similar
SHA-1 issuance by Visa root
#1391087 RESOLVED Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 76% similar
Visa: Non-BR-Compliant Certificate Issuance
#1414039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-11-02 · Closed 2024-05-09 · 75% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1350615 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-03-25 · Closed 2022-11-14 · 75% similar
Camerfirma: Startcom are issuing by proxy using Camerfirma
#1398259 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-09-08 · Closed 2023-02-22 · 75% similar
SECOM: Non-BR-Compliant OCSP Responders
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 75% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1393557 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 75% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action