← Start Commercial (StartCom) Ltd. cases
Bugzilla #1386894 Ca Certificate Compliance Certificate Misissuance

StartCom: Non-BR-Compliant Certificate Issuance — adding Certinomis cross-signed StartCom intermediates to OneCRL

RESOLVED DUPLICATE Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns StartCom intermediate certificates that were cross-signed by Certinomis and that issued many certificates that did not comply with the Mozilla Baseline Requirements (BR). The issue was raised after the intermediates were disclosed in the CCADB, and the thread states that the intermediates were disclosed 111 days after issuance, despite Mozilla policy requiring disclosure within one week of intermediate certificate creation and before any leaf or subordinate certificates are issued from the intermediate. Mozilla staff requested that OneCRL entries be created for two specific Certinomis-signed intermediate certificates and a revocations.txt file so compatibility testing could be run. The thread also includes discussion that some certificates were revoked and that others were not revoked due to reasons described by StartCom (e.g., pre-certificates/test certificates and certificates with specific errors). The CA certificates were discussed as being retained until a successful WebTrust audit, after which they were disclosed in the CCADB with policy documents and audit reports. The bug was ultimately marked as a duplicate of bug 1402158.

Model: gpt-5.4-nano Generated: 2026-06-13 17:02 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.86 10 comments
Chronology
  1. Mozilla staff requested OneCRL entries and revocation artifacts for two Certinomis cross-signed StartCom intermediate certificates after identifying BR non-compliance and late intermediate disclosure.
Thread Activity
  1. Mozilla representative — Reported that many non-BR-compliant SSL certificates were issued from StartCom intermediate certs cross-signed by Certinomis and proposed adding both intermediates to OneCRL due to late disclosure.
  2. Mozilla representative — Asked Mark to create OneCRL entries for two specific Certinomis-signed intermediate certificates and to generate a revocations.txt file for compat testing.
  3. Certinomis representative — Stated the two CA certificates were retained until a successful WebTrust audit and that they were disclosed in the CCADB after audit/policy updates, and argued that non-compliant TLS certificates should be revoked.
  4. WoSign CA Limited — Disputed the characterization of the issuance as sloppy/non-compliant, stated they had not started issuing using the new path, and explained why some listed certificates were revoked or not revoked.
  5. Mozilla representative — Confirmed OneCRL staging would be handled and suggested approving pending changes in bug 1385914 before staging.
  6. WoSign CA Limited — Said pre-certificates and certificates related to different curves were revoked, but questioned why Certinomis-signed certificates needed to be added to OneCRL.
  7. Community commenter — Cited CCADB/Mozilla policy language requiring intermediate certificates (including revoked ones) to be entered into the database and requiring disclosure within one week before subordinate issuance.
  8. Insufficient representative — Said bug 1385914 was finalized and that this should be a clean state to add to OneCRL.
  9. Certinomis representative — Argued that because the cross-signed intermediates were not available to StartCom until after the audit, no TLS certificates could have been issued using them publicly-trusted, and questioned the goal of adding them to OneCRL.
  10. Mozilla representative — Noted the bug was marked as a duplicate of bug 1402158.
Participants
Mozilla representative Certinomis representative WoSign CA Limited Insufficient representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 100% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1409760 RESOLVED Certificate Misissuance Opened 2017-10-18 · Closed 2022-11-14 · 79% similar
StartCom: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
#1267049 RESOLVED Certificate Misissuance Opened 2016-04-24 · Closed 2023-02-22 · 78% similar
Izenpe: EV certificate with various issues
#1313873 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 78% similar
SHA-1 issuance by DocuSign root
#1339339 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-02-14 · Closed 2023-02-22 · 78% similar
DigiCert: Non-BR Compliant Certificates - missing CP/CPS OID
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 78% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1319609 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 77% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1398427 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 77% similar
Let's Encrypt: CAA Misissuances

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action