← DigiCert cases
Bugzilla #1937693 Certificate Misissuance

DigiCert now China CCP Dog,PEM uploaded

RESOLVED INVALID DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The reporter submitted a certificate-related complaint involving a TLS interception (MITM) scenario while using a China VPN and viewing YouTube. They attached PEM files and claimed that the MITM used DigiCert and that the domain was Facebook, and also referenced a DigiCert domain of “*.internet.org.” A Mozilla reviewer asked the reporter to share the supposed end-entity certificate for Facebook or other domains. The reporter provided a certificate chain attachment, and the Mozilla reviewer checked the certificate presented and CT logging details. The reviewer stated that the certificate appeared valid for Facebook, that it was logged in CT, and that “internet.org” appears to be a domain registered by Meta Platforms, Inc., with redirects to meta.com and another valid TLS certificate. The bug was closed as INVALID, with an offer to reopen if additional evidence of certificate mis-issuance or CA compromise is provided.

Model: gpt-5.4-nano Generated: 2026-06-13 11:46 UTC Revised: 2026-06-16 19:19 UTC Confidence: 0.86 5 comments
Chronology
  1. A CA Program bug was filed with PEM attachments alleging DigiCert certificates were used in a MITM scenario.
Thread Activity
  1. Community commenter — Created the bug and attached a PEM file, alleging MITM used DigiCert for Facebook and also referenced *.internet.org.
  2. Community commenter — Asked for the supposed end-entity certificate for Facebook (or other domains) corresponding to the attached issuing CA certificate.
  3. Community commenter — Uploaded a certificate chain PEM attachment.
  4. Community commenter — Confirmed the requested information was provided.
  5. Mozilla representative — Reviewed CT and crt.sh details, stated the certificate appeared valid for Facebook and that internet.org appears to be registered by Meta, then closed the bug as INVALID while requesting additional evidence for mis-issuance or CA compromise.
Participants
Community commenter Mozilla representative
External References
Similar Local Cases
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 86% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 86% similar
DigiCert: Invalid localityName
#1759122 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-11 · Closed 2022-11-14 · 86% similar
DigiCert: EV for Onion addresses without Tor Service Descriptor
#1586604 RESOLVED Certificate Misissuance Validation Issue Opened 2019-10-06 · Closed 2022-11-14 · 78% similar
DigiCert: TERENA: No localityName in EV precert
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 78% similar
DigiCert: Misissuance detected by PKIMetal
#1518555 RESOLVED Certificate Misissuance Opened 2019-01-08 · Closed 2023-02-22 · 77% similar
DigiCert: Use of forbidden subjectPublicKeyInfo algorithm
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 77% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 76% similar
DigiCert: Non-BR-Compliant OCSP Responders

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action