← Internet Security Research Group cases
Bugzilla #1853719 Certificate Misissuance

Once Revoked Let's Encrypt Certificate Actively Signing Malware

RESOLVED INVALID Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened with an allegation that an older Let’s Encrypt certificate (and an alternate version) is “actively signing malware.” The reporter provided VirusTotal relations and other references, and argued that the certificate should not be reintroduced to public trust. Mozilla CA Program staff asked for evidence of private key compromise or misuse, noting that public certificates can be copied and misused and that the primary concern is private key handling and use. After reviewing the references provided, Mozilla staff stated they still could not identify any CA-related vulnerability, exploit, or threat, and suggested the allegation was unsubstantiated. The bug was intended to be closed as Invalid, and the current resolution is INVALID. The thread also includes additional links and discussion from the reporter, but Mozilla staff continued to request a CA-related concern beyond public bundling with malware.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.74 9 comments
Chronology
  1. A bug was filed alleging that a Let’s Encrypt certificate is being used to sign malware.
  2. Mozilla staff indicated an intent to close the bug as Invalid.
  3. The bug was resolved as INVALID.
Thread Activity
  1. Community commenter — Filed the report claiming an old Let’s Encrypt CA/certificate is actively signing malware and provided VirusTotal and other references.
  2. Mozilla representative — Asked for evidence of private key compromise or misuse and said the allegation about malware signing was unsubstantiated based on public certificate bundling.
  3. Mozilla representative — Stated an intent to close the bug on Wed 27-Sep-2023 as Invalid.
  4. Community commenter — Responded with additional links and references, including a related older Bugzilla thread and other web pages.
  5. Mozilla representative — Said they still could not identify any CA-related vulnerability, exploit, or threat and asked what other concern existed.
  6. Community commenter — Added more references and argued that previously revoked certificates being distributed by malware is significant.
  7. Community commenter — Provided a Mozilla TLS Observatory certs/description link for the ISRG Root X1 certificate.
Participants
Community commenter Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1966515 RESOLVED Certificate Misissuance Opened 2025-05-14 · Closed 2025-06-04 · 68% similar
Let's Encrypt: Issuance for Invalid Internationalized Domain Name
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 68% similar
DigiCert: Invalid localityName
#1937693 RESOLVED Certificate Misissuance Opened 2024-12-17 · 68% similar
DigiCert now China CCP Dog,PEM uploaded
#1717046 RESOLVED Certificate Misissuance Opened 2021-06-17 · Closed 2022-11-14 · 68% similar
Sectigo: potentially invalid organizational validation certificates
#1777270 RESOLVED Certificate Misissuance Opened 2022-06-29 · Closed 2023-02-22 · 68% similar
Certainly: Intermediate certificates with wrong time encoding
#1645708 RESOLVED Certificate Misissuance Opened 2020-06-14 · Closed 2023-02-22 · 67% similar
QuoVadis: EV serialNumber with "none"
#1809864 RESOLVED Certificate Misissuance Opened 2023-01-12 · Closed 2024-05-09 · 67% similar
Google Trust Services: Mis-issued certificates for citi.com subdomain due to lack of CAA record checking
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 67% similar
e-commerce monitoring GmbH: SCT in precertificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action