← Start Commercial (StartCom) Ltd. cases
Bugzilla #471702 Ca Security Vulnerability Security Incident

StartCom's key for bogus www.mozilla.com certificate should be destroyed

RESOLVED INVALID Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves StartCom's issuance of a certificate for www.mozilla.com, which was obtained under questionable circumstances by Eddy Nigg, who claimed to expose validation failures at a competitor CA. The certificate was installed on a publicly accessible server, and Nigg threatened to publish the private key. The thread discusses the implications of this incident, including calls for the destruction of the private key. Ultimately, the bug was resolved with the status 'INVALID', as it was determined that Mozilla could not compel the destruction of the key, although it was noted that Nigg had taken down the server hosting the certificate.

Model: gpt-4o-mini Generated: 2026-06-13 12:10 UTC Revised: 2026-06-16 18:34 UTC Confidence: 0.85 17 comments
Chronology
  1. StartCom's certificate for www.mozilla.com was obtained under questionable circumstances.
Thread Activity
  1. Samj representative — Reported that StartCom's certificate for www.mozilla.com was fraudulently obtained.
  2. Startcom representative — Claimed the issue was resolved to Mozilla's satisfaction and left it to Mozilla to close the bug.
  3. Mozilla representative — Stated that the request to destroy the private key could not be compelled, leading to the bug's invalidation.
Participants
Samj representative Startcom representative Mozilla representative Anode representative
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#499178 RESOLVED Ca Security Vulnerability Self Reported Incident Opened 2009-06-18 · Closed 2022-11-14 · 79% similar
Clarification requested regarding remediation of StartCom certificate issuance vulnerability
#1283498 RESOLVED Security Incident Self Reported Incident Opened 2016-06-30 · Closed 2022-11-14 · 68% similar
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 67% similar
DigiCert: OCSP responder returning invalid responses
#1675684 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-11-06 · Closed 2023-02-22 · 67% similar
DigiCert: Private Keys Disclosed by Customers as Part of CSR
#1878106 RESOLVED Ca Security Vulnerability Security Incident Opened 2024-02-01 · Closed 2024-03-08 · 67% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 66% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1816806 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-02-15 · Closed 2023-03-09 · 66% similar
DigiCert: OCSP not responding issue
#1820269 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-03-03 · Closed 2024-06-30 · 66% similar
DigiCert: 4 CRLs unavailable or not responding

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action