← Start Commercial (StartCom) Ltd. cases
Bugzilla #499178
Ca Security Vulnerability
Self Reported Incident
Clarification requested regarding remediation of StartCom certificate issuance vulnerability
RESOLVED
WORKSFORME
Start Commercial (StartCom) Ltd.
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves StartCom's disclosure of a vulnerability in its certificate issuance system that allowed users to request certificates for any domain. The issue was identified internally, prompting StartCom to seek clarification on the remediation steps taken. StartCom confirmed that an audit was conducted, and no invalid certificates were found during subsequent checks. The case was resolved with StartCom's actions deemed satisfactory, and it continues to undergo annual audits.
Chronology
- StartCom disclosed a vulnerability in its certificate issuance system.
Thread Activity
- Samj representative — Requested clarification on how the vulnerability was remediated and if all issued certificates were valid.
- Startcom representative — Explained that the issue was due to a bug in user input checking and that a report was published after detection.
- Startcom representative — Confirmed that StartCom was under audit during the incident and that no failed validations were found.
- Startcom representative — Stated that the procedures for incident handling were followed correctly and that the audit confirmed compliance.
Participants
Community commenter
External References
Similar Local Cases
Camerfirma: Startcom are issuing by proxy using Camerfirma
StartCom's key for bogus www.mozilla.com certificate should be destroyed
StartCom: OCSP responder often returns "unknown" for recently-issued certificates
Disclosure of StartCom CA Certificates
StartCom: Action Items
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB
Google Trust Services: Short OCSP outage