← Start Commercial (StartCom) Ltd. cases
Bugzilla #471702 · Certificate Misissuance
StartCom's key for bogus www.mozilla.com certificate should be destroyed
Start Commercial (StartCom) Ltd. · RESOLVED
AI Summary
This case addresses the fraudulent issuance of a certificate for www.mozilla.com by StartCom, which was obtained under questionable circumstances. The certificate's existence raised significant security concerns, prompting calls for the destruction of the associated private key. The case was ultimately resolved with the conclusion that the request for destruction was invalid, as it was beyond the authority of the bug system to enforce such a request.
Chronology
- Initial report of fraudulent certificate issuance
- Case marked as resolved
Participants
Sam Johnston
Frank Hecker
Eddy Nigg
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
DigiCert: Underscores - Intuit
DigiCert: Incorrectly issued EV Certificate
DigiCert: RapidSSL CAA Mis-Issuance: Lookup failure on DNSSEC-signed zone
DigiCert / Verizon: Reserved/Intranet domain name
DigiCert / Wells Fargo: Invalid DNS names
DigiCert: DigiCert issued cert with CN too long