← Internet Security Research Group cases
Bugzilla #1414039
Ca Certificate Compliance
Self Reported Incident
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
RESOLVED
FIXED
Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
The case involves a certificate for google.tg issued by Let's Encrypt after a compromise of the .tg registry. Google alerted Mozilla that this certificate was being used maliciously. In response, Mozilla added the certificate to OneCRL and confirmed that both Let's Encrypt and Comodo had halted issuance of certificates for .tg domains. The incident was confirmed to have started on October 25, 2017, and was resolved by November 10, 2017. Follow-up actions included contacting other CAs to re-validate certificates issued during the compromise period.
Chronology
- Google reported a certificate for google.tg was issued after a registry compromise.
- Mozilla added the compromised certificate to OneCRL.
- The .tg registry confirmed the resolution of the compromise.
Thread Activity
- Mozilla representative — Received information about a compromised certificate for google.tg.
- Mozilla representative — Agreed to add the certificate to OneCRL.
- Mozilla representative — Confirmed that the entry for the compromised certificate has been added to OneCRL.
- Mozilla representative — Received confirmation from the .tg registry about the resolution of the compromise.
Participants
Mozilla representative
Insufficient representative
External References
Similar Local Cases
Let's Encrypt: Improper encoding of wildcard certificates
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
DigiCert / Justica: Invalid DNS names
StartCom: Action Items
Camerfirma: Startcom are issuing by proxy using Camerfirma
NetLock: Non-BR-Compliant Certificate Issuance
DigiCert / Telecom Italia: Several Problems