Certinomis: Cross-signing of StartCom intermediate certs and delayed CCADB reporting
This case concerns Certinomis cross-signing of StartCom intermediate certificates and a delay in disclosing those cross-signed intermediates in the Common CA Database (CCADB). The issue was raised because the cross-signed intermediates were disclosed 111 days after issuance, and the intermediates issued many certificates that did not comply with the Baseline Requirements. Certinomis stated that the two CA certificates were retained until a full successful WebTrust audit, and that it disclosed the certificates in CCADB with corresponding policy documents and audit reports before sending them to StartCom. Mozilla discussed remediation, including adding the certificates to OneCRL, and Certinomis provided an incident report describing when it disclosed the cross-signed intermediates and subsequent actions. The thread states that the plan was to add the certificates to OneCRL (tracked via Bug 1402158), and that the CCADB “Revocation Status” was updated. The bug is marked RESOLVED with resolution FIXED, and the reporter indicated the bug could be closed after the CCADB updates.
- The cross-signed intermediates issued by Certinomis had a notBefore date of 2017-04-13.
- Certinomis disclosed two cross-signed StartCom intermediate certificates in CCADB.
- Certinomis and others discussed non-BR-compliant certificates issued by StartCom ICAs in mozilla.dev.security.policy.
- CCADB was updated with “Revocation Status” for the relevant records.
- Community commenter — Opened the issue describing Certinomis cross-signing of StartCom intermediates and noting the 111-day delay in CCADB disclosure, with links to misissued certificates.
- Community commenter — Explained Certinomis retained the CA certificates until a successful WebTrust audit, then disclosed them in CCADB with policy documents and audit reports before sending them to StartCom.
- Community commenter — Asked what information or remediation is needed from Certinomis, pointing to related StartCom-side discussion and bugs.
- Community commenter — Stated the current plan was to add the certificates to OneCRL and discussed accountability questions for misissuances enabled by the cross-sign.
- Community commenter — Requested an incident report and CCADB “Revocation Status” updates after revocation and CRL addition.
- Community commenter — Provided an incident report including how Certinomis became aware, a timeline of actions, and details about problematic certificates and planned ARL signing.
- Community commenter — Reported that CCADB had been updated with “Revocation Status.”
- Community commenter — Indicated the bug may be closed and asked for agreement.