← IPS Certification Authority s.l. ipsCA cases
Bugzilla #536406 Certificate Problem Report

IPSCA SSL certificates not accepted in Mozilla (duplicate of bug 529286)

RESOLVED DUPLICATE IPS Certification Authority s.l. ipsCA
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug report states that new IPSCA SSL certificates were not being accepted by Mozilla, while IE8 accepted them. The reporter compared access to https://collab.ctrip.ufl.edu in Mozilla versus IE8 and reported that IE8 loaded the page while Mozilla did not trust the certificate. During discussion, a participant from StartCom indicated the issue was related to DNS resolution rather than the certificate itself, noting SERVFAIL/timeouts when reaching the server. The reporter acknowledged the DNS issue and said they were following another thread related to IPSCA certs and believed the current thread could be closed. Another participant later stated that the problem appeared to be that new certificates were issued from a root not present in Mozilla, most likely the root from bug 529286, and suggested marking this bug as resolved. The bug was ultimately marked as a duplicate of bug 529286.

Model: gpt-5.4-nano Generated: 2026-06-13 12:14 UTC Revised: 2026-06-16 19:09 UTC Confidence: 0.86 10 comments
Chronology
  1. A third party reported that IPSCA-issued SSL certificates were not trusted by Mozilla while IE8 accepted them.
  2. Participants discussed whether the issue was due to DNS or a missing Mozilla-trusted root and identified a likely link to bug 529286.
  3. The bug was marked as a duplicate of bug 529286.
Thread Activity
  1. Ichp representative — Reported that new IPSCA SSL certificates were not accepted in Mozilla for https://collab.ctrip.ufl.edu, while IE8 accepted them, and asked whether an update was planned.
  2. Mit representative — Moved the issue to a more accurate component.
  3. Startcom representative — Said the issue was not the certificate and indicated Mozilla could not find/reach the server (DNS/SERVFAIL/timeouts).
  4. Ichp representative — Suggested it might be a DNS issue and confirmed the site is SSL-only.
  5. Startcom representative — Confirmed it was a DNS issue and referenced an IP lookup URL.
  6. Ichp representative — Acknowledged the DNS issue and said they thought the thread could be closed.
  7. Rossde representative — Asked whether this was a duplicate of bug 529286.
  8. Startcom representative — Agreed it was related and stated new certificates were issued from a root not in Mozilla, likely from bug 529286, and that the bug could be marked resolved.
  9. Mozilla representative — Marked the bug as a duplicate of bug 529286.
Participants
Ichp representative Mit representative Startcom representative Rossde representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#529286 RESOLVED Root Inclusion Opened 2009-11-17 · Closed 2022-11-14 · 49% similar
Add ipsCA Global and ipsCA Main root certificates
#1015767 RESOLVED Certificate Misissuance Opened 2014-05-25 · Closed 2022-11-14 · 35% similar
startcom: still issuing < 2048 bit certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action