StartCom: Non-BR-Compliant Certificate Issuance — adding Certinomis cross-signed StartCom intermediates to OneCRL
This case concerns StartCom intermediate certificates that were cross-signed by Certinomis and that issued many certificates that did not comply with the Mozilla Baseline Requirements (BR). The issue was raised after the intermediates were disclosed in the CCADB, and the thread states that the intermediates were disclosed 111 days after issuance, despite Mozilla policy requiring disclosure within one week of intermediate certificate creation and before any leaf or subordinate certificates are issued from the intermediate. Mozilla staff requested that OneCRL entries be created for two specific Certinomis-signed intermediate certificates and a revocations.txt file so compatibility testing could be run. The thread also includes discussion that some certificates were revoked and that others were not revoked due to reasons described by StartCom (e.g., pre-certificates/test certificates and certificates with specific errors). The CA certificates were discussed as being retained until a successful WebTrust audit, after which they were disclosed in the CCADB with policy documents and audit reports. The bug was ultimately marked as a duplicate of bug 1402158.
- Mozilla staff requested OneCRL entries and revocation artifacts for two Certinomis cross-signed StartCom intermediate certificates after identifying BR non-compliance and late intermediate disclosure.
- Mozilla representative — Reported that many non-BR-compliant SSL certificates were issued from StartCom intermediate certs cross-signed by Certinomis and proposed adding both intermediates to OneCRL due to late disclosure.
- Mozilla representative — Asked Mark to create OneCRL entries for two specific Certinomis-signed intermediate certificates and to generate a revocations.txt file for compat testing.
- Certinomis representative — Stated the two CA certificates were retained until a successful WebTrust audit and that they were disclosed in the CCADB after audit/policy updates, and argued that non-compliant TLS certificates should be revoked.
- WoSign CA Limited — Disputed the characterization of the issuance as sloppy/non-compliant, stated they had not started issuing using the new path, and explained why some listed certificates were revoked or not revoked.
- Mozilla representative — Confirmed OneCRL staging would be handled and suggested approving pending changes in bug 1385914 before staging.
- WoSign CA Limited — Said pre-certificates and certificates related to different curves were revoked, but questioned why Certinomis-signed certificates needed to be added to OneCRL.
- Community commenter — Cited CCADB/Mozilla policy language requiring intermediate certificates (including revoked ones) to be entered into the database and requiring disclosure within one week before subordinate issuance.
- Insufficient representative — Said bug 1385914 was finalized and that this should be a clean state to add to OneCRL.
- Certinomis representative — Argued that because the cross-signed intermediates were not available to StartCom until after the audit, no TLS certificates could have been issued using them publicly-trusted, and questioned the goal of adding them to OneCRL.
- Mozilla representative — Noted the bug was marked as a duplicate of bug 1402158.