Closed Bug 1269183 Opened 9 years ago Closed 9 years ago

StartCom: Certificates using secp256k1

Categories

(CA Program :: CA Certificate Root Program, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED WONTFIX

People

(Reporter: kurt, Assigned: eddy_nigg)

References

Details

(Whiteboard: BR Compliance)

Hi, I see a few certificates like https://crt.sh/?id=17662860 that use secp256k1, which isn't one of the 3 allowed curves by the BR.
Assignee: kwilson → eddy_nigg
StartCom has only recently started to support elliptic curves and will allow only the currently permitted signatures. Remaining certificates with non-compliant curves will be replaced and revoked.
Flags: sec-bounty?
Flags: needinfo?(eddy_nigg)
Flags: sec-bounty?
Flags: needinfo?(eddy_nigg)
Whiteboard: BR Compliance
Summary: startcom: Certificates using secp256k1 → StartCom: Certificates using secp256k1
Resolving; if StartCom becomes trusted again, they are unlikely to have the same issues. Gerv
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → WONTFIX
Product: mozilla.org → NSS
Product: NSS → CA Program
You need to log in before you can comment on or make changes to this bug.