← Start Commercial (StartCom) Ltd. cases
Bugzilla #1386891
Certificate Misissuance
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB
RESOLVED
FIXED
Start Commercial (StartCom) Ltd.
AI Summary
This case addresses the cross-signing of StartCom intermediate certificates by Certinomis and the significant delay in reporting this action in the Common CA Database (CCADB). Certinomis disclosed the certificates 111 days after issuance, which raised compliance concerns regarding the Baseline Requirements. The incident prompted discussions about accountability for misissued certificates and led to the decision to revoke the cross-signed intermediates. The case has been resolved with updates to the CCADB reflecting the revocation status.
Chronology
- Certinomis disclosed two cross-signed ICAs for StartCom in CCADB.
- Revocation status updated in CCADB.
Participants
Kathleen Wilson
Franck Leroy
Ryan Sleevi
Gervase Markham
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
NetLock: Non-BR-Compliant Certificate Issuance
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
Amazon Trust Services: CAA Misissuances
Microsec: Non-BR-Compliant Certificate Issuance
Disig: Non-BR-Compliant Certificate Issuance
SHA-1 issuance by Visa root
StartCom: 'un-revoking' intermediate certificates