StartCom's key for bogus www.mozilla.com certificate should be destroyed
This case involves StartCom's issuance of a certificate for www.mozilla.com, which was obtained under questionable circumstances by Eddy Nigg, who claimed to expose validation failures at a competitor CA. The certificate was installed on a publicly accessible server, and Nigg threatened to publish the private key. The thread discusses the implications of this incident, including calls for the destruction of the private key. Ultimately, the bug was resolved with the status 'INVALID', as it was determined that Mozilla could not compel the destruction of the key, although it was noted that Nigg had taken down the server hosting the certificate.
- StartCom's certificate for www.mozilla.com was obtained under questionable circumstances.
- Samj representative — Reported that StartCom's certificate for www.mozilla.com was fraudulently obtained.
- Startcom representative — Claimed the issue was resolved to Mozilla's satisfaction and left it to Mozilla to close the bug.
- Mozilla representative — Stated that the request to destroy the private key could not be compelled, leading to the bug's invalidation.