← Start Commercial (StartCom) Ltd. cases
Bugzilla #1269183
Policy Compliance
StartCom: Certificates using secp256k1
RESOLVED
Start Commercial (StartCom) Ltd.
AI Summary
This case addresses the use of secp256k1 certificates by StartCom, which are not compliant with the allowed curves under the Baseline Requirements. The issue was raised by Kurt Roeckx, highlighting non-compliance with the established standards. StartCom acknowledged the issue and committed to replacing and revoking non-compliant certificates. The case was ultimately resolved with a WONTFIX status, indicating that no further action was taken at that time.
Chronology
- Initial report of secp256k1 certificate usage
- StartCom's response regarding compliance and future actions
- Case resolution noted by Mozilla representative
Participants
Kurt Roeckx
Eddy Nigg (StartCom)
Gervase Markham
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
GoDaddy: Valid 1024 certificates
SwissSign: BRs require full annual audits
SHA-1 issuance by GlobalSign root
Distrust ISRG Subordinate Certificate and Remove It Until the CA is Compliant with Mozilla Policies
Amazon Trust Services: Forbidden Domain Validation Method 3.2.2.4.6
startcom: still issuing < 2048 bit certificates
DigiCert: Verizon CPS lacks CPR problem reporting instructions
Amazon Trust Services: CP/CPS does not specify key compromise methods