← Visa cases
Bugzilla #1315016 Self Reported Incident

SHA-1 issuance by Visa root

RESOLVED FIXED Visa
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves Visa's issuance of SHA-1 certificates in violation of the CA/Browser Forum Baseline Requirements. The issue was raised by Mozilla after discovering that two certificates were issued in 2016 using SHA-1. Visa acknowledged the misissuance and explained that the certificates were replaced with SHA-2 certificates by June 2016. Despite initial delays in revocation, Visa confirmed that the SHA-1 certificates were revoked by December 2016, following Mozilla's insistence on compliance with their policies.

Model: gpt-4o-mini Generated: 2026-06-13 14:07 UTC Revised: 2026-06-16 18:12 UTC Confidence: 0.85 24 comments
Chronology
  1. Mozilla identifies SHA-1 certificates issued by Visa.
  2. Visa confirms revocation of SHA-1 certificates.
Thread Activity
  1. Mozilla representative — Mozilla raises concerns about SHA-1 certificates issued by Visa.
  2. Visa — Visa explains the context of SHA-1 issuance and outlines a remediation plan.
  3. Visa — Visa confirms that the SHA-1 certificates have been revoked.
Participants
Mozilla representative Visa
External References
Similar Local Cases
#1391087 RESOLVED Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 100% similar
Visa: Non-BR-Compliant Certificate Issuance
#1398261 RESOLVED Self Reported Incident Opened 2017-09-08 · Closed 2023-02-22 · 100% similar
Visa: Non-BR-Compliant OCSP Responders
#1393557 RESOLVED Self Reported Incident Incident Opened 2017-08-24 · Closed 2023-02-22 · 79% similar
GlobalSign: Non-BR-Compliant Certificate Issuance -- RSA key smaller than 2048 bits
#1350615 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-03-25 · Closed 2022-11-14 · 78% similar
Camerfirma: Startcom are issuing by proxy using Camerfirma
#1397961 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-09-07 · Closed 2023-02-22 · 78% similar
DigiCert / Justica: Invalid DNS names
#1311832 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2016-10-20 · Closed 2023-01-27 · 77% similar
StartCom: Action Items
#1398259 RESOLVED Self Reported Incident Incident Closure Request Opened 2017-09-08 · Closed 2023-02-22 · 77% similar
SECOM: Non-BR-Compliant OCSP Responders
#1414039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-11-02 · Closed 2024-05-09 · 76% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action