← Start Commercial (StartCom) Ltd. cases
Bugzilla #1402158 Ca Certificate Compliance Ca Security Vulnerability

Add Certinomis cross-signed StartCom certificates to OneCRL

RESOLVED FIXED Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case requests adding two Certinomis cross-signed StartCom root certificates to OneCRL. The request was triggered by a need to ensure the certificates are present in OneCRL, and it included the issuer commonName and certificate serial numbers for both certificates. Certinomis stated that it planned to revoke these certificates during a key ceremony planned in October. After the certificates were added, the Mozilla CA Program representative confirmed they had been added to OneCRL. The representative then asked Certinomis to update the 'Revocation Status' for their records in the Common CA Database after the planned revocation. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:10 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.50 4 comments
Chronology
  1. Mozilla requested that two Certinomis cross-signed StartCom root certificates be added to OneCRL.
  2. Certinomis stated it planned to revoke the certificates during an October key ceremony.
  3. The certificates were confirmed as added to OneCRL, with a request to update CCADB revocation status after revocation.
Thread Activity
  1. Community commenter — Requested adding two specified Certinomis - Root CA certificates (by issuer commonName and serial numbers) to OneCRL.
  2. Community commenter — Said Certinomis planned to revoke the certificates during the next key ceremony planned in October.
  3. Community commenter — Confirmed the certificates were added to OneCRL and asked Certinomis to update the 'Revocation Status' in CCADB after revocation.
Participants
Community commenter
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#611283 RESOLVED Ca Certificate Compliance Opened 2010-11-11 · Closed 2022-11-14 · 60% similar
StartCom cert not working in Firefox 4 beta
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 60% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1386894 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-03 · Closed 2023-02-22 · 60% similar
StartCom: Non-BR-Compliant Certificate Issuance -- adding Certnomis intermediates to OneCRL
#499178 RESOLVED Ca Security Vulnerability Self Reported Incident Opened 2009-06-18 · Closed 2022-11-14 · 59% similar
Clarification requested regarding remediation of StartCom certificate issuance vulnerability
#1311832 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2016-10-20 · Closed 2023-01-27 · 59% similar
StartCom: Action Items
#1350615 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-03-25 · Closed 2022-11-14 · 59% similar
Camerfirma: Startcom are issuing by proxy using Camerfirma
#2008782 RESOLVED Ca Certificate Compliance Opened 2026-01-06 · Closed 2026-02-18 · 59% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #1 - mass certificate revocation plan
#471702 RESOLVED Ca Security Vulnerability Security Incident Opened 2008-12-31 · Closed 2022-11-14 · 57% similar
StartCom's key for bogus www.mozilla.com certificate should be destroyed

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action