← Cisco cases
Bugzilla #1374809 Ca Security Vulnerability

Leaked private key for Cisco certificate (revoked and added to OneCRL)

RESOLVED FIXED Cisco
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case reports that Cisco leaked the private key to one of their certificates. The certificate was revoked, and the Mozilla CA Program team discussed whether revocation should be handled by subject/public key. Kathleen Wilson asked whether the CRL had been updated and requested confirmation of the correct CRL URL and the PEM of the certificate. Quovadis (via Stephen Davidson) stated that the certificate serial number 66:17:0c:e2:ec:8b:7d:88:b4:e2:eb:73:2e:73:8f:e3:a6:7c:f6:72 was revoked for Key Compromise and provided the issuing CA CRL URL. Kathleen later confirmed that the certificate had been added to OneCRL. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 15:00 UTC Revised: 2026-06-16 18:02 UTC Confidence: 0.50 5 comments
Chronology
  1. Cisco’s leaked private key certificate was revoked for key compromise and reported for CA Program handling.
  2. The revoked certificate was added to OneCRL.
Thread Activity
  1. Mozilla representative — Reported that Cisco leaked a private key for a certificate, noted it was revoked, and suggested adding it to OneCRL while sharing serial number and DNS name details.
  2. Mozilla representative — Suggested revoking by subject/public key because private key disclosure was the particularly bad aspect.
  3. Mozilla representative — Asked whether the CRL was updated, whether a specific CRL URL was correct, and requested the PEM of the certificate.
  4. Quovadis representative — Confirmed the certificate serial was revoked for Key Compromise and provided the issuing CA CRL URL.
  5. Mozilla representative — Confirmed the certificate was added to OneCRL.
Participants
Mozilla representative Quovadis representative
Similar Local Cases
#1427034 RESOLVED Ca Security Vulnerability Security Incident Opened 2017-12-25 · Closed 2024-05-09 · 54% similar
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
#1421820 RESOLVED Ca Security Vulnerability Certificate Misissuance Opened 2017-11-29 · Closed 2022-11-14 · 47% similar
Microsoft DSRE PKI: Microsoft shares wildcard certificates among cloud instances
#1484798 RESOLVED Ca Security Vulnerability Revocation Issue Opened 2018-08-20 · Closed 2024-05-09 · 44% similar
DigiCert: *.sslsimplified.com compromised private key
#1402158 RESOLVED Ca Certificate Compliance Ca Security Vulnerability Opened 2017-09-21 · Closed 2022-11-14 · 44% similar
Add Certinomis Cross-Signed StartCom certs to OneCRL
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 41% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 40% similar
DigiCert: OCSP responder returning invalid responses
#1386894 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-03 · Closed 2023-02-22 · 40% similar
StartCom: Non-BR-Compliant Certificate Issuance -- adding Certnomis intermediates to OneCRL
#988633 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2014-03-26 · Closed 2023-02-22 · 40% similar
GoDaddy: improperly encoded certificate issued by Go Daddy Secure Certification Authority

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action