← Start Commercial (StartCom) Ltd. cases
Bugzilla #471702
Certificate Misissuance
StartCom's key for bogus www.mozilla.com certificate should be destroyed
RESOLVED
Start Commercial (StartCom) Ltd.
AI Summary
This case addresses the fraudulent issuance of a certificate for www.mozilla.com by StartCom, which was obtained under questionable circumstances. The certificate's existence raised significant security concerns, prompting calls for the destruction of the associated private key. The case was ultimately resolved with the conclusion that the request for destruction was invalid, as it was beyond the authority of the bug system to enforce such a request.
Chronology
- Initial report of fraudulent certificate issuance
- Case marked as resolved
Participants
Sam Johnston
Frank Hecker
Eddy Nigg
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
StartCom: CAA Mis-Issuance on CNAME pointing directly to restrictive CAA record
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
StartCom: 'un-revoking' intermediate certificates
Logius: Staat der Nederlanden CA trust issue (WiV)
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
Certisign: Misissuance detected by PKIMetal
DigiCert: Underscores - Intuit