DigiCert now China CCP Dog,PEM uploaded
The reporter submitted a certificate-related complaint involving a TLS interception (MITM) scenario while using a China VPN and viewing YouTube. They attached PEM files and claimed that the MITM used DigiCert and that the domain was Facebook, and also referenced a DigiCert domain of “*.internet.org.” A Mozilla reviewer asked the reporter to share the supposed end-entity certificate for Facebook or other domains. The reporter provided a certificate chain attachment, and the Mozilla reviewer checked the certificate presented and CT logging details. The reviewer stated that the certificate appeared valid for Facebook, that it was logged in CT, and that “internet.org” appears to be a domain registered by Meta Platforms, Inc., with redirects to meta.com and another valid TLS certificate. The bug was closed as INVALID, with an offer to reopen if additional evidence of certificate mis-issuance or CA compromise is provided.
- A CA Program bug was filed with PEM attachments alleging DigiCert certificates were used in a MITM scenario.
- Community commenter — Created the bug and attached a PEM file, alleging MITM used DigiCert for Facebook and also referenced *.internet.org.
- Community commenter — Asked for the supposed end-entity certificate for Facebook (or other domains) corresponding to the attached issuing CA certificate.
- Community commenter — Uploaded a certificate chain PEM attachment.
- Community commenter — Confirmed the requested information was provided.
- Mozilla representative — Reviewed CT and crt.sh details, stated the certificate appeared valid for Facebook and that internet.org appears to be registered by Meta, then closed the bug as INVALID while requesting additional evidence for mis-issuance or CA compromise.