← EDICOM cases
Bugzilla #1397830 Certificate Misissuance Revocation Issue

EDICOM: Signing SHA-1 OCSP responses with unconstrained certificate

RESOLVED FIXED EDICOM
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case was opened after an external reporter told EDICOM that its OCSP responder signs OCSP responses with SHA-1 using a certificate trusted by Mozilla for server authentication, which the reporter said violates Mozilla Root Store Policy 2.5 section 5.1.1. The reporter also raised a security concern related to chosen-prefix attacks because the OCSP response reflects an attacker-supplied nonce. EDICOM later stated that it had technical issues disabling SHA-1 when signing OCSP responses and decided not to continue supporting the previous Certification Authority Root. EDICOM said it would proceed with including a new root (referenced as Bug 1239329) and suggested starting the process to remove its “ACEDICOM Root” from the trusted PKI root. Mozilla staff indicated that the bug could be resolved with the outcome of removing the root, and later the Security Issue flag was agreed to be removed. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:08 UTC Revised: 2026-06-16 18:28 UTC Confidence: 0.50 8 comments
Chronology
  1. A report was filed alleging EDICOM’s OCSP responder signs OCSP responses with SHA-1 using an unconstrained certificate.
  2. EDICOM stated it could not disable SHA-1 for OCSP signing and decided to move away from the previous root.
  3. Mozilla filed a request to remove the old ACEDICOM root certificate (Bug 1400013), while the new root inclusion request remained on hold pending a BR self-assessment.
  4. Mozilla indicated the bug could be resolved based on removing the root.
  5. The Security Issue flag was agreed to be removed and made public.
Thread Activity
  1. Mm representative — Reported that EDICOM’s OCSP responder signs OCSP responses with SHA-1 using a certificate trusted for server authentication, citing a Root Store Policy violation and attaching evidence.
  2. Mozilla representative — Asked Raúl to acknowledge the bug promptly, provide a timeline, and submit an incident report.
  3. Edicom representative — Said EDICOM found technical issues disabling SHA-1 for OCSP signing and decided not to support the previous root; suggested starting removal of the old ACEDICOM root and referenced the new root inclusion process.
  4. Mozilla representative — Stated she filed Bug 1400013 to remove the old ACEDICOM root and noted the new root inclusion request was on hold pending a BR Self Assessment.
  5. Mozilla representative — Asked whether the bug could be resolved with the outcome of removing the root.
  6. Community commenter — Suggested removing the Security Issue flag.
  7. Mozilla representative — Agreed to remove the Security Issue flag and said she would ask someone to fix it.
  8. Emmah representative — Confirmed making the change public per Kathleen.
Participants
Mm representative Mozilla representative Edicom representative Community commenter Emmah representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1391429 RESOLVED Certificate Misissuance Revocation Issue Opened 2017-08-17 · Closed 2024-02-27 · 72% similar
GoDaddy: Non-BR-Compliant Certificate Issuance
#1736020 RESOLVED Certificate Misissuance Opened 2021-10-15 · Closed 2023-02-22 · 68% similar
Telia: Invalid email contact address was used for few domains
#1391000 RESOLVED Ca Certificate Compliance Incident Revocation Issue Opened 2017-08-16 · Closed 2023-02-22 · 68% similar
IdenTrust: Non-BR-Compliant Certificate Issuance
#1523680 RESOLVED Revocation Issue Incident Opened 2019-01-29 · Closed 2023-02-22 · 68% similar
Actalis: Non BR Compliant OCSP Responder
#1634795 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-01 · Closed 2023-02-22 · 67% similar
Google Trust Services: Incorrect revocation data temporarily served for GTS Y3 & Y4
#1536831 RESOLVED Ca Certificate Compliance Revocation Issue Remediation Tracking Opened 2019-03-20 · Closed 2023-02-22 · 67% similar
GDCA: Insufficient Serial Number Entropy
#1321354 RESOLVED Revocation Issue Incident Opened 2016-11-30 · Closed 2022-11-14 · 67% similar
DocuSign France - Internal names certificates under a technically-constrained subordinate CA
#1639804 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 65% similar
Sectigo: Failure to revoke key-compromised certificate within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action