← TrustCor Systems cases
Bugzilla #1579284 Ca Certificate Compliance Certificate Misissuance

TrustCor: Non-audited intermediate certificates

RESOLVED FIXED TrustCor Systems
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns TrustCor intermediate certificates that were not audited but still chain up to Mozilla-trusted root certificates. The issue was identified after the reporter learned from Mozilla disclosure-related CRT.sh pages that TrustCor had non-revoked, superseded intermediate certificates that were not audited, yet remained technically trusted by Firefox via included root certificates. The thread states that TrustCor regenerated their root certificates per a referenced bug, and that the older intermediates were created under superseded roots. TrustCor’s Policy Authority agreed that revoking the listed certificates was the best path rather than including the superseded certificates in the audit scope. TrustCor revoked the listed certificates effective 2019-09-13 and updated its CRL and OCSP services accordingly, and asked that the certificates be added to OneCRL. The CA also instructed updating CCADB to indicate the revocation status, and later confirmed that the certificates were revoked and CCADB was updated. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 19:34 UTC Revised: 2026-06-16 18:12 UTC Confidence: 0.50 5 comments
Chronology
  1. TrustCor case opened regarding non-audited intermediate certificates that chain to Mozilla-trusted roots.
  2. TrustCor revoked the listed intermediate certificates and updated CRL/OCSP services.
  3. CCADB revocation status update was completed per TrustCor instructions.
  4. Reporter confirmed revocation and CCADB updates; case marked resolved.
Thread Activity
  1. Community commenter — Reported that TrustCor has non-revoked, superseded intermediate certificates that are not audited but chain to Mozilla-trusted roots, and listed specific roots/intermediates that need revocation or audit-scope inclusion.
  2. Community commenter — Stated TrustCor’s Policy Authority agreed to revoke the listed certificates (effective 2019-09-13), updated CRL/OCSP, and provided the revoked certificate details.
  3. Community commenter — Requested that CCADB be updated to mark the intermediates as revoked, linking to the CCADB instructions.
  4. Community commenter — Confirmed CCADB was updated per the instructions.
  5. Community commenter — Confirmed the certificates are revoked and CCADB reflects their revocation status.
Participants
Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1404403 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-29 · Closed 2023-02-22 · 77% similar
SwissSign: Two certs issued with same issuer and serial number
#1397965 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-07 · Closed 2023-02-22 · 77% similar
DigiCert / Swiss Government: CommonName not in SANs
#1436173 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-02-06 · Closed 2023-02-22 · 72% similar
DigiCert: SCEE / Justica: Non-BR-Compliant Certificate Issuance
#1386894 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-03 · Closed 2023-02-22 · 71% similar
StartCom: Non-BR-Compliant Certificate Issuance -- adding Certnomis intermediates to OneCRL
#1691704 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-02-09 · Closed 2023-02-22 · 70% similar
SwissSign: Certificate with key length 4098 bit
#1866091 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2023-11-22 · Closed 2023-12-11 · 70% similar
SwissSign: EV JurisdictionStateOrProvinceName - one certificate not selected for revocation
#1502957 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-10-29 · Closed 2023-02-22 · 70% similar
Camerfirma: MULTICERT Misissuance and missing audits
#1512270 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-12-05 · Closed 2023-02-22 · 70% similar
Microsec: Validity period greater than 825 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action