← Visa cases
Bugzilla #1315016
Self Reported Incident
SHA-1 issuance by Visa root
RESOLVED
FIXED
Visa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves Visa's issuance of SHA-1 certificates in violation of the CA/Browser Forum Baseline Requirements. The issue was raised by Mozilla after discovering that two certificates were issued in 2016 using SHA-1. Visa acknowledged the misissuance and explained that the certificates were replaced with SHA-2 certificates by June 2016. Despite initial delays in revocation, Visa confirmed that the SHA-1 certificates were revoked by December 2016, following Mozilla's insistence on compliance with their policies.
Chronology
- Mozilla identifies SHA-1 certificates issued by Visa.
- Visa confirms revocation of SHA-1 certificates.
Thread Activity
- Mozilla representative — Mozilla raises concerns about SHA-1 certificates issued by Visa.
- Visa — Visa explains the context of SHA-1 issuance and outlines a remediation plan.
- Visa — Visa confirms that the SHA-1 certificates have been revoked.
Participants
Mozilla representative
Visa
External References
Similar Local Cases
Visa: Non-BR-Compliant Certificate Issuance
Visa: Non-BR-Compliant OCSP Responders
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
Camerfirma: Startcom are issuing by proxy using Camerfirma
DigiCert / Justica: Invalid DNS names
StartCom: Action Items
SECOM: Non-BR-Compliant OCSP Responders
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.