← DigiNotar cases
Bugzilla #682956
Certificate Misissuance
Investigate *.google.com certificate issued by DigiNotar and used by Iran government?
RESOLVED
DUPLICATE
DigiNotar
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves an investigation into a certificate for *.google.com issued by DigiNotar, which was reportedly used by the Iranian government. The issue was raised by a user who provided details and links to discussions about the certificate. The bug was marked as a duplicate of another case that was already known to Mozilla. Kathleen Wilson confirmed that the situation was being addressed urgently according to Mozilla's Security Bugs Policy. The bug was ultimately resolved as a duplicate.
Chronology
- User reported a certificate issued by DigiNotar for *.google.com.
Thread Activity
- Entrust representative — Created attachment with details about the certificate and links to discussions.
- Joshtriplett representative — Triaged the bug and marked it as a duplicate of an existing case.
- Mozilla representative — Confirmed that the issue was being worked on urgently.
- Reedloden representative — *** This bug has been marked as a duplicate of bug 682927 ***
Participants
Entrust representative
Joshtriplett representative
Mozilla representative
Hexapodia representative
Reedloden representative
External References
Similar Local Cases
SHA-1 issuance by GlobalSign root
DigiCert: Non-BR-Compliant OCSP Responders
Amazon Trust Services: CAA Misissuances
Swisscom: certificates without DNS names in subjectAltName
startcom: still issuing < 2048 bit certificates
Asseco DS / Certum: non-audited intermediate certificate
StartCom: Certificates using secp256k1
Camerfirma: Potential Mis-Issuance based on CAA records