← Start Commercial (StartCom) Ltd. cases
Bugzilla #1386891 Self Reported Incident

Certinomis: Cross-signing of StartCom intermediate certs and delayed CCADB reporting

RESOLVED FIXED Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Certinomis cross-signing of StartCom intermediate certificates and a delay in disclosing those cross-signed intermediates in the Common CA Database (CCADB). The issue was raised because the cross-signed intermediates were disclosed 111 days after issuance, and the intermediates issued many certificates that did not comply with the Baseline Requirements. Certinomis stated that the two CA certificates were retained until a full successful WebTrust audit, and that it disclosed the certificates in CCADB with corresponding policy documents and audit reports before sending them to StartCom. Mozilla discussed remediation, including adding the certificates to OneCRL, and Certinomis provided an incident report describing when it disclosed the cross-signed intermediates and subsequent actions. The thread states that the plan was to add the certificates to OneCRL (tracked via Bug 1402158), and that the CCADB “Revocation Status” was updated. The bug is marked RESOLVED with resolution FIXED, and the reporter indicated the bug could be closed after the CCADB updates.

Model: gpt-5.4-nano Generated: 2026-06-13 17:02 UTC Revised: 2026-06-16 18:46 UTC Confidence: 0.86 9 comments
Chronology
  1. The cross-signed intermediates issued by Certinomis had a notBefore date of 2017-04-13.
  2. Certinomis disclosed two cross-signed StartCom intermediate certificates in CCADB.
  3. Certinomis and others discussed non-BR-compliant certificates issued by StartCom ICAs in mozilla.dev.security.policy.
  4. CCADB was updated with “Revocation Status” for the relevant records.
Thread Activity
  1. Community commenter — Opened the issue describing Certinomis cross-signing of StartCom intermediates and noting the 111-day delay in CCADB disclosure, with links to misissued certificates.
  2. Community commenter — Explained Certinomis retained the CA certificates until a successful WebTrust audit, then disclosed them in CCADB with policy documents and audit reports before sending them to StartCom.
  3. Community commenter — Asked what information or remediation is needed from Certinomis, pointing to related StartCom-side discussion and bugs.
  4. Community commenter — Stated the current plan was to add the certificates to OneCRL and discussed accountability questions for misissuances enabled by the cross-sign.
  5. Community commenter — Requested an incident report and CCADB “Revocation Status” updates after revocation and CRL addition.
  6. Community commenter — Provided an incident report including how Certinomis became aware, a timeline of actions, and details about problematic certificates and planned ARL signing.
  7. Community commenter — Reported that CCADB had been updated with “Revocation Status.”
  8. Community commenter — Indicated the bug may be closed and asked for agreement.
Participants
Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1024143 RESOLVED Self Reported Incident Opened 2014-06-11 · Closed 2022-11-14 · 80% similar
Disclosure of StartCom CA Certificates
#1283498 RESOLVED Security Incident Self Reported Incident Opened 2016-06-30 · Closed 2022-11-14 · 70% similar
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
#1311832 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2016-10-20 · Closed 2023-01-27 · 70% similar
StartCom: Action Items
#499178 RESOLVED Ca Security Vulnerability Self Reported Incident Opened 2009-06-18 · Closed 2022-11-14 · 69% similar
Clarification requested regarding remediation of StartCom certificate issuance vulnerability
#1350615 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-03-25 · Closed 2022-11-14 · 69% similar
Camerfirma: Startcom are issuing by proxy using Camerfirma
#1684442 RESOLVED Self Reported Incident Opened 2020-12-29 · Closed 2023-02-22 · 68% similar
DigiCert: SHA-1 intermediate issued after 2016-01-01
#1532399 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-03-04 · Closed 2023-02-22 · 68% similar
TrustCor: Insufficient Serial Number Entropy
#1006479 RESOLVED Self Reported Incident Opened 2014-05-06 · Closed 2022-11-14 · 68% similar
StartCom: OCSP responder often returns "unknown" for recently-issued certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action