← Trustis cases
Bugzilla #1353838 Certificate Misissuance

Trustis: SHA-1 serverAuth cert issued in November 2016

RESOLVED Trustis
AI Summary

Trustis issued a SHA-1 serverAuth certificate for hmrcset.trustis.com in November 2016, which was later found to be non-compliant with Mozilla's policies. Following reports and discussions, Trustis revoked the certificate and replaced it with a SHA-256 version. An additional SHA-1 certificate for getset.trustis.com was also identified, leading to further scrutiny of Trustis's certificate issuance processes. The case has been resolved with updates to their compliance practices.

Model: gpt-4o-mini Generated: 2026-06-13 14:13 UTC Confidence: 0.95
Chronology
  1. Initial report of SHA-1 certificate
  2. Trustis revoked the SHA-1 certificate
  3. Incident report provided by Trustis
  4. Trustis acknowledged mis-issuance and updated compliance practices
Participants
Kathleen Wilson Blake Morgan
Similar Local Cases
#1017562 RESOLVED Certificate Misissuance Opened 2014-05-29 · Closed 2022-11-14 · 60% similar
Trustis: Certificate not version 3
#1315016 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 51% similar
SHA-1 issuance by Visa root
#1335132 RESOLVED Certificate Misissuance Opened 2017-01-30 · Closed 2023-02-22 · 51% similar
DigiCert: Verizon mis-issued test certificates
#1313873 RESOLVED Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 49% similar
SHA-1 issuance by DocuSign root
#1319609 RESOLVED Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 49% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1397954 RESOLVED Certificate Misissuance Opened 2017-09-07 · Closed 2023-02-22 · 48% similar
DigiCert / Siemens: Insufficient Serial Number Entropy
#1353827 RESOLVED Certificate Misissuance Opened 2017-04-05 · Closed 2023-02-22 · 48% similar
DigiCert: DigiCert issued cert with CN too long
#1414039 RESOLVED Certificate Misissuance Opened 2017-11-02 · Closed 2024-05-09 · 47% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action