Mozilla accuses Chinese certificate authority WoSign of back-dating SHA-1 certificates and other violations, proposes no longer trusting WoSign certificates
Context & Ripple Effects
Mozilla's distrust proposal is the escalation of a month-old incident: as documented earlier in September, WoSign issued a valid SSL certificate for GitHub's primary domain to a subdomain customer and declined to revoke it even after being alerted. Back-dated SHA-1 certificates are the second alleged violation stacked on top of that mis-issuance.
The stakes go beyond one CA: because browser vendors control the root trust stores, Mozilla's move effectively decides whether WoSign can sell TLS at all. The related coverage shows where this path leads — Google's Chrome 61 distrust of WoSign and StartCom and Microsoft joining Apple, Google, and Mozilla in disabling the CA's certificates.
First-order effects
- If Mozilla's proposal ships, every site running a WoSign-issued certificate faces browser warnings in Firefox unless it reissues from another CA, hitting WoSign's paying customers first.
- WoSign loses the credibility needed to contest the findings publicly, since the back-dating allegation implies deliberate concealment rather than an operational error like the GitHub mis-issuance.
Second-order effects
- The other major browser vendors face pressure to match Mozilla's decision or explain why their trust stores still vouch for a CA Firefox rejects — a coordination dynamic the coverage confirms played out when Microsoft joined Apple, Google, and Mozilla in disabling WoSign and StartCom certificates.
- StartCom, WoSign's subsidiary, inherits the penalty through shared ownership, collapsing two CAs' businesses into one enforcement action.
Third-order effects
- Browser makers are consolidating de facto regulatory power over the global TLS supply chain: audit failures now end in commercial death rather than probation, a template later applied when Firefox and Edge moved against TrustCor over its defense-contractor ties.
- Certificate buyers gain an argument for concentrating on a small set of heavily scrutinized CAs, accelerating consolidation of the CA market around vendors that survive multi-browser audits.
The trend: Web trust is shifting from self-regulated certificate authorities to browser vendors acting as the effective regulators, with mis-issuance scandals triggering coordinated cross-vendor distrust rather than fines or remediation.