← Certainly LLC cases
Bugzilla #1777270
Certificate Misissuance
Certainly: Intermediate certificates with wrong time encoding
RESOLVED
DUPLICATE
Certainly LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
The reporter identified intermediate certificates with wrong time encoding and noted that the affected certificates were already revoked. The reporter stated they did not see an incident report for this issue and provided links to the certificates on crt.sh. Mozilla staff responded that the certificates were issued by GoDaddy, not Certainly. The bug was then marked as a duplicate of bug 1777128. The thread does not describe any CA remediation action by Certainly beyond the duplicate resolution.
Chronology
- A third party reported intermediate certificates with wrong time encoding that were already revoked.
Thread Activity
- Lebihan representative — Reported intermediate certificates with wrong time encoding, said they were already revoked, and provided crt.sh links while noting no incident report was visible.
- Mozilla representative — Clarified the certificates were issued by GoDaddy (not Certainly) and marked the bug as a duplicate of bug 1777128.
Participants
Lebihan representative
Mozilla representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
DigiCert: Invalid localityName
KIR S.A.: Invalid organizationName
DigiCert: TERENA: Insufficient validation of organizationalUnitName
DigiCert: EV for Onion addresses without Tor Service Descriptor
Once Revoked Let's Encrypt Certificate Actively Signing Malware
QuoVadis: EV serialNumber with "none"
Sectigo: potentially invalid organizational validation certificates
Microsec: Incorrect OCSP Delegated Responder Certificate