← certSIGN cases
Bugzilla #1718675 Certificate Problem Report

certSIGN: CPS specifies md5 and sha1WithRSAEncryption as allowed signature types

RESOLVED FIXED certSIGN
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug concerns certSIGN’s CPS text stating that the “Signature Algorithm” field in Table 7.1 allows md5WithRSAEncryption and sha1WithRSAEncryption (in addition to sha256WithRSAEncryption). The issue was raised after certSIGN was informed by a Bugzilla ticket on 2021-06-29 11:21 PDT that the CPS specifies these algorithms as usable signature types. certSIGN stated that there were no certificates issued with MD5 or SHA-1, and that technical controls were in place such that issuance using md5 or sha1 is not permitted. certSIGN reviewed the issue, drafted and internally validated a response, and then planned CPS updates to remove md5 and sha1 from Table 7.1. certSIGN reported that the planned steps were completed and that CPS version 1.33 was published in the certSIGN repository. Mozilla later indicated it would close the bug as “fixed,” and the bug is resolved with resolution “FIXED.”

Model: gpt-5.4-nano Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 18:22 UTC Confidence: 0.50 5 comments
Chronology
  1. A Bugzilla ticket informed certSIGN that its CPS Table 7.1 listed md5WithRSAEncryption and sha1WithRSAEncryption as allowed signature algorithms.
  2. certSIGN reviewed the issue and drafted and internally validated a response plan to update the CPS documentation.
  3. certSIGN obtained approvals to publish an updated CPS version removing md5 and sha1 from Table 7.1.
  4. certSIGN published CPS version 1.33 and reported the bug as fully resolved.
Thread Activity
  1. Thisisntrocket representative — Reported that certSIGN ROOT CA CPS section 7.1.1 Table 7.1 lists md5WithRSAEncryption and sha1WithRSAEncryption as allowed signature algorithms, and argued md5 and sha1 should be removed or moved to legacy profiles.
  2. certSIGN — Described how certSIGN became aware (via the Bugzilla ticket), stated no md5/sha1 certificates were issued and issuance using md5/sha1 is not permitted, and outlined remediation steps to update and publish CPS.
  3. certSIGN — Confirmed the planned remediation steps were completed and that CPS version 1.33 was published in the certSIGN repository.
  4. certSIGN — Asked Mozilla to review the published CPS v1.33 and mark the bug as Resolved or Fixed.
  5. Mozilla representative — Stated the bug would be closed as "fixed" next Wednesday, 14-July-2021.
Participants
Thisisntrocket representative certSIGN Mozilla representative
Similar Local Cases
#1762707 RESOLVED Certificate Misissuance Opened 2022-04-02 · Closed 2023-02-22 · 43% similar
certSIGN: Subscriber precertificate without Certificate Policies
#1833667 RESOLVED Audit Document Audit Finding Opened 2023-05-17 · Closed 2023-11-19 · 42% similar
certSIGN: Findings in 2023 ETSI Audit for certSIGN ROOT CA G2 - Audit Incident Report
#1886624 RESOLVED Self Reported Incident Opened 2024-03-20 · Closed 2025-06-04 · 42% similar
certSIGN: Certificates with incorrect Subject attribute order
#1845803 RESOLVED Certificate Problem Report Opened 2023-07-27 · Closed 2023-09-08 · 41% similar
GlobalSign: Three (3) revoked precertificates with reasonCode “certificateHold”
#1897134 RESOLVED Audit Finding Opened 2024-05-16 · Closed 2024-09-06 · 41% similar
certSIGN: Findings in 2024 ETSI Audit - Audit Incident Report
#1963546 RESOLVED Ca Documents Audit Finding Opened 2025-04-30 · Closed 2025-05-19 · 41% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report
#1705657 RESOLVED Ca Certificate Compliance Revocation Issue Opened 2021-04-16 · Closed 2023-02-22 · 40% similar
KIR S.A.: Many certificates with OCSP Unknown
#1674886 RESOLVED Certificate Misissuance Opened 2020-11-02 · Closed 2023-02-22 · 40% similar
certSIGN: misissued an OV SSL certificate with no organizationName and localityName, instead of a DV SSL as requested by client

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action