← Internet Security Research Group cases
Bugzilla #1414039 Ca Certificate Compliance Self Reported Incident

Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case involves a certificate for google.tg issued by Let's Encrypt after a compromise of the .tg registry. Google alerted Mozilla that this certificate was being used maliciously. In response, Mozilla added the certificate to OneCRL and confirmed that both Let's Encrypt and Comodo had halted issuance of certificates for .tg domains. The incident was confirmed to have started on October 25, 2017, and was resolved by November 10, 2017. Follow-up actions included contacting other CAs to re-validate certificates issued during the compromise period.

Model: gpt-4o-mini Generated: 2026-06-13 11:59 UTC Revised: 2026-06-16 19:12 UTC Confidence: 0.85 28 comments
Chronology
  1. Google reported a certificate for google.tg was issued after a registry compromise.
  2. Mozilla added the compromised certificate to OneCRL.
  3. The .tg registry confirmed the resolution of the compromise.
Thread Activity
  1. Mozilla representative — Received information about a compromised certificate for google.tg.
  2. Mozilla representative — Agreed to add the certificate to OneCRL.
  3. Mozilla representative — Confirmed that the entry for the compromised certificate has been added to OneCRL.
  4. Mozilla representative — Received confirmation from the .tg registry about the resolution of the compromise.
Participants
Mozilla representative Insufficient representative
External References
Similar Local Cases
#1446080 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-03-15 · Closed 2023-02-22 · 88% similar
Let's Encrypt: Improper encoding of wildcard certificates
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 86% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 86% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1397961 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-09-07 · Closed 2023-02-22 · 86% similar
DigiCert / Justica: Invalid DNS names
#1311832 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2016-10-20 · Closed 2023-01-27 · 85% similar
StartCom: Action Items
#1350615 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-03-25 · Closed 2022-11-14 · 85% similar
Camerfirma: Startcom are issuing by proxy using Camerfirma
#1391056 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-08-16 · Closed 2023-02-22 · 85% similar
NetLock: Non-BR-Compliant Certificate Issuance
#1397960 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-09-07 · Closed 2023-02-22 · 85% similar
DigiCert / Telecom Italia: Several Problems

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action