← DocuSign (OpenTrust/Keynectis) cases
Bugzilla #1313873 Certificate Misissuance

SHA-1 issuance by DocuSign root

RESOLVED DocuSign (OpenTrust/Keynectis)
AI Summary

This case addresses the issuance of SHA-1 certificates by DocuSign's root CA, which is against Mozilla's policies. The certificates were issued erroneously due to a failure in organizational and technical controls. DocuSign has since revoked the misissued certificates and is implementing measures to prevent future occurrences. The CA's compliance with the Baseline Requirements is under scrutiny, and corrective actions are being taken.

Model: gpt-4o-mini Generated: 2026-06-13 14:07 UTC Confidence: 0.95
Chronology
  1. Initial report of SHA-1 certificates issued by DocuSign
  2. DocuSign provides details on the misissuance and corrective actions
  3. Mozilla acknowledges the corrective measures taken by DocuSign
Participants
Gervase Markham Kathleen Wilson Erwann Abalea
Similar Local Cases
#1315016 RESOLVED Certificate Misissuance Opened 2016-11-03 · Closed 2022-11-14 · 60% similar
SHA-1 issuance by Visa root
#1313872 RESOLVED Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 59% similar
SHA-1 issuance by DigiCert roots
#1397969 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 57% similar
DigiCert / Inteso San Paulo: Double dot characters
#1398428 RESOLVED Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 56% similar
Amazon Trust Services: CAA Misissuances
#1293366 RESOLVED Certificate Misissuance Opened 2016-08-08 · Closed 2022-11-14 · 56% similar
WoSign issued SHA-1 SSL certs and backdated the issuance date on SSL certificates
#1398427 RESOLVED Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 56% similar
Let's Encrypt: CAA Misissuances
#1319609 RESOLVED Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 56% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1283498 RESOLVED Certificate Misissuance Opened 2016-06-30 · Closed 2022-11-14 · 55% similar
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action