← Start Commercial (StartCom) Ltd. cases
Bugzilla #499178 Ca Security Vulnerability Self Reported Incident

Clarification requested regarding remediation of StartCom certificate issuance vulnerability

RESOLVED WORKSFORME Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves StartCom's disclosure of a vulnerability in its certificate issuance system that allowed users to request certificates for any domain. The issue was identified internally, prompting StartCom to seek clarification on the remediation steps taken. StartCom confirmed that an audit was conducted, and no invalid certificates were found during subsequent checks. The case was resolved with StartCom's actions deemed satisfactory, and it continues to undergo annual audits.

Model: gpt-4o-mini Generated: 2026-06-13 12:12 UTC Revised: 2026-06-16 18:36 UTC Confidence: 0.85 17 comments
Chronology
  1. StartCom disclosed a vulnerability in its certificate issuance system.
Thread Activity
  1. Samj representative — Requested clarification on how the vulnerability was remediated and if all issued certificates were valid.
  2. Startcom representative — Explained that the issue was due to a bug in user input checking and that a report was published after detection.
  3. Startcom representative — Confirmed that StartCom was under audit during the incident and that no failed validations were found.
  4. Startcom representative — Stated that the procedures for incident handling were followed correctly and that the audit confirmed compliance.
Participants
Community commenter
External References
Similar Local Cases
#1350615 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-03-25 · Closed 2022-11-14 · 80% similar
Camerfirma: Startcom are issuing by proxy using Camerfirma
#471702 RESOLVED Ca Security Vulnerability Security Incident Opened 2008-12-31 · Closed 2022-11-14 · 79% similar
StartCom's key for bogus www.mozilla.com certificate should be destroyed
#1006479 RESOLVED Self Reported Incident Opened 2014-05-06 · Closed 2022-11-14 · 79% similar
StartCom: OCSP responder often returns "unknown" for recently-issued certificates
#1024143 RESOLVED Self Reported Incident Opened 2014-06-11 · Closed 2022-11-14 · 79% similar
Disclosure of StartCom CA Certificates
#1311832 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2016-10-20 · Closed 2023-01-27 · 79% similar
StartCom: Action Items
#1283498 RESOLVED Security Incident Self Reported Incident Opened 2016-06-30 · Closed 2022-11-14 · 76% similar
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
#1386891 RESOLVED Self Reported Incident Opened 2017-08-02 · Closed 2023-02-22 · 69% similar
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB
#2032511 RESOLVED Ca Security Vulnerability Self Reported Incident Opened 2026-04-16 · Closed 2026-05-29 · 68% similar
Google Trust Services: Short OCSP outage

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action