← DigiCert cases
Bugzilla #1313872 Self Incident Disclosure

SHA-1 issuance by DigiCert roots

RESOLVED WONTFIX DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened after Mozilla security policy discussions identified SHA-1 certificates chaining up to Mozilla-trusted DigiCert roots that had not been brought up on the list or in Bugzilla. DigiCert representatives responded that the affected issuing CAs were outside DigiCert’s direct control, and they worked with those partners to determine what happened. For Vodafone, DigiCert stated that Vodafone controls the issuing CA, that Vodafone was migrating to new SHA-2 infrastructure with audits scheduled, and that DigiCert had communicated to partners that SHA-1 use is forbidden. For Siemens, DigiCert stated the Siemens issuing CA is under Siemens Europe control and described it as a legacy CA they hoped to decommission, while later Siemens provided details including that SHA-1 issuance was prevented by their Server RA software and that two specific SHA-1 certificates were issued due to an erroneously applied exception process, after which the certificates were revoked and employees re-informed. The Mozilla bug was ultimately marked WONTFIX, with Mozilla stating that as long as DigiCert continues its plan and takes robust action about further SHA-1 issuance, no further action would be taken. The thread also included discussion of revocation scheduling and a plan to revoke at least one intermediate for failing to fix issuance systems, with a proposed revocation date of Dec 1.

Model: gpt-5.4-nano Generated: 2026-06-13 11:02 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.50 9 comments
Chronology
  1. A Mozilla CA Program bug was filed regarding SHA-1 certificates chaining to DigiCert roots.
  2. DigiCert provided partner-specific explanations for Vodafone and requested to post separate replies per incident.
  3. DigiCert stated it would revoke a Nets Norway intermediate and discussed a revocation schedule.
  4. Mozilla set the bug to WONTFIX based on DigiCert’s stated plan and actions.
Thread Activity
  1. Mozilla representative — Gerv cited mozilla.dev.security.policy posts listing SHA-1 certificates chaining to DigiCert roots and asked DigiCert to explain CP/CPS, audit status, control of issuing CAs, and technical enforcement.
  2. Mozilla representative — Kathleen asked Jeremy to look into the issue and update the bug with the requested information.
  3. DigiCert — Jeremy said separate replies per incident were acceptable and provided Vodafone-related answers about SHA-1 prohibition, audit scheduling, and control of the issuing CA.
  4. DigiCert — Jeremy provided Siemens-related information, stating Siemens controls the issuing CA and that DigiCert had communicated with Siemens about the BR breach.
  5. Mozilla representative — Gerv agreed that separate replies for each incident were fine.
  6. Eishundo representative — Pat compared the situation to another SHA-1-related issue and suggested revocation and adding to revocation lists, referencing other bugs.
  7. DigiCert — Jeremy stated they decided to revoke the Nets Norway intermediate, discussed a proposed revocation schedule, and described reliance on audits plus plans for monthly/quarterly statements and cablint checks.
  8. Mozilla representative — Gerv set the bug to WONTFIX, pointing to a mozilla.dev.security.policy thread and stating no further action would be taken if DigiCert continues robust action.
  9. Community commenter — Ben Wilson posted Siemens’ statement describing CP/CPS algorithm handling, Siemens audit approach, control of the issuing CA, and details of erroneous exception-based SHA-1 issuance followed by revocation and employee re-informing.
Participants
Mozilla representative DigiCert Eishundo representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1397954 RESOLVED Incident Revocation Issue Opened 2017-09-07 · Closed 2023-02-22 · 68% similar
DigiCert / Siemens: Insufficient Serial Number Entropy
#1397960 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-09-07 · Closed 2023-02-22 · 68% similar
DigiCert / Telecom Italia: Several Problems
#1304895 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-09-22 · Closed 2023-02-22 · 67% similar
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
#1389172 RESOLVED Ca Certificate Compliance Revocation Issue Opened 2017-08-10 · Closed 2023-02-22 · 67% similar
DigiCert: Certificate Issues Identified on the Mailing List
#1397961 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-09-07 · Closed 2023-02-22 · 67% similar
DigiCert / Justica: Invalid DNS names
#1397969 RESOLVED Self Reported Incident Opened 2017-09-08 · Closed 2023-02-22 · 67% similar
DigiCert / Inteso San Paulo: Double dot characters
#1417771 RESOLVED Ca Documents Incident Opened 2017-11-16 · Closed 2024-06-30 · 67% similar
DigiCert: Symantec non-constrained/non-disclosed intermediate CA certificates
#1335132 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-01-30 · Closed 2023-02-22 · 66% similar
DigiCert: Verizon mis-issued test certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action