← Start Commercial (StartCom) Ltd. cases
Bugzilla #1369359
Certificate Misissuance
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
RESOLVED
FIXED
Start Commercial (StartCom) Ltd.
AI Summary
StartCom Ltd. was reported for issuing certificates with unvalidated domain names and incorrect field values. The incident arose from testing related to Certificate Transparency (CT) logging, which led to the creation of fake certificates that were immediately revoked. StartCom acknowledged the issue and provided a report detailing the incident and remediation steps taken to prevent future occurrences. The certificates in question were not part of the legitimate issuance process and were only for testing purposes.
Chronology
- Initial report of mis-issued certificates
- StartCom responds and explains the situation
- Discussion on potential overlap with another bug
Participants
Gervase Markham
Inigo Szczygłowski
Ryan Sleevi
External References
Similar Local Cases
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
Asseco DS / Certum: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
Microsec: Non-BR-Compliant Certificate Issuance
Disig: Non-BR-Compliant Certificate Issuance
StartCom: 'un-revoking' intermediate certificates
NetLock: Non-BR-Compliant Certificate Issuance
E-Tugra: Improper DER results in failure to comply with RFC 5280 - Invalid characters in PrintableString