← Start Commercial (StartCom) Ltd. cases
Bugzilla #1386894
Certificate Problem Report
StartCom: Non-BR-Compliant Certificate Issuance -- adding Certnomis intermediates to OneCRL
RESOLVED
DUPLICATE
Start Commercial (StartCom) Ltd.
AI Summary
The case addresses the issuance of non-Baseline Requirements (BR) compliant SSL certificates from StartCom's intermediate certificates, which were cross-signed by Certinomis. Concerns were raised regarding the lack of timely disclosure of these intermediates, which were not disclosed until 111 days after issuance. The resolution involved adding the two problematic intermediates to OneCRL due to their history of issuing non-compliant certificates. The case was marked as a duplicate of another bug, indicating that the issues raised were already being addressed in a separate thread.
Chronology
- Initial report of non-BR-compliant certificate issuance
- Case marked as a duplicate of bug 1402158
Participants
Kathleen Wilson
Franck Leroy
Iñigo
Peter Bowen
JC
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Add Certinomis Cross-Signed StartCom certs to OneCRL
StartCom: IV without localityName or stateOrProvinceName
Clarification requested regarding remediation of StartCom certificate issuance vulnerability
StartCom: public exponent is 1
Camerfirma: Startcom are issuing by proxy using Camerfirma
Startcom: CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone
StartCom cert not working in Firefox 4 beta
StartCom: OCSP responder often returns "unknown" for recently-issued certificates