Remove StartCom CA from Mozilla for violation of CA policy
The bug was filed to remove StartCom (StartCom) from Mozilla’s CA program, alleging a violation of Mozilla CA policy related to revocation of certificates believed to be compromised. The reporter stated that StartCom demanded additional payments, including from paying customers, to revoke certificates believed to be compromised. The reporter argued that revocation obligations under the Mozilla CA policy apply regardless of customer payments, and that charging may be acceptable for re-issuing but not for the revocation itself. Another participant pointed to bug 994033 and marked this bug as a duplicate. The bug’s resolution is listed as DUPLICATE, and the thread does not describe any separate remediation action by Mozilla or StartCom beyond the duplicate handling.
- A bug was opened requesting removal of the StartCom CA from Mozilla’s CA program over alleged CA policy non-compliance regarding revocation.
- The bug was marked as a duplicate of bug 994033.
- Mtu representative — Reported that StartCom was in violation of Mozilla CA policy by demanding additional payments to revoke certificates believed to be compromised, and argued revocation should occur without such demands.
- Mtu representative — Clarified the interpretation that StartCom’s revocation obligations apply regardless of payments, distinguishing revocation from re-issuance.
- Kuix representative — Said the discussion belongs on the dev-security-policy mailing list and noted the bug was marked as a duplicate of bug 994033.
- Community commenter — Shared an experiment URL related to revocation.
- Community commenter — Commented that, based on StartCom’s reply, the internet can’t trust them anymore.
- Disabled representative — Discussed the experiment in relation to StartCom’s policy and suggested it could trigger revocation and potential reimbursement issues.