← WoSign CA Limited cases
Bugzilla #1293366 Certificate Misissuance

WoSign issued SHA-1 SSL certs and backdated the issuance date on SSL certificates

RESOLVED WoSign CA Limited
AI Summary

WoSign CA Limited was found to have issued SHA-1 SSL certificates with backdated issuance dates. This issue was reported by Christiaan Ottow and raised concerns about the potential misuse of a non-public API that allowed backdated certificate issuance. WoSign responded by revoking the affected certificates and implementing measures to prevent future mis-issuance, including logging all issued certificates to public CT logs.

Model: gpt-4o-mini Generated: 2026-06-13 14:04 UTC Confidence: 0.95
Chronology
  1. Issue reported by Christiaan Ottow
  2. Bug filed and initial responses from WoSign
  3. WoSign confirmed the mis-issuance and provided details
  4. Further discussions on the implications and actions taken
  5. Mozilla took action regarding WoSign
Participants
Kathleen Wilson Richard Wang Christiaan Ottow Filip Jirsak Gervase Markham
Similar Local Cases
#1414039 RESOLVED Certificate Misissuance Opened 2017-11-02 · Closed 2024-05-09 · 59% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1315016 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 57% similar
SHA-1 issuance by Visa root
#1283498 RESOLVED Certificate Misissuance Opened 2016-06-30 · Closed 2022-11-14 · 57% similar
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
#1313873 RESOLVED Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 56% similar
SHA-1 issuance by DocuSign root
#1319609 RESOLVED Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 55% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1397969 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 55% similar
DigiCert / Inteso San Paulo: Double dot characters
#1313872 RESOLVED Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 53% similar
SHA-1 issuance by DigiCert roots
#1398427 RESOLVED Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 52% similar
Let's Encrypt: CAA Misissuances

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action