Leaked private key for Cisco certificate (revoked and added to OneCRL)
The case reports that Cisco leaked the private key to one of their certificates. The certificate was revoked, and the Mozilla CA Program team discussed whether revocation should be handled by subject/public key. Kathleen Wilson asked whether the CRL had been updated and requested confirmation of the correct CRL URL and the PEM of the certificate. Quovadis (via Stephen Davidson) stated that the certificate serial number 66:17:0c:e2:ec:8b:7d:88:b4:e2:eb:73:2e:73:8f:e3:a6:7c:f6:72 was revoked for Key Compromise and provided the issuing CA CRL URL. Kathleen later confirmed that the certificate had been added to OneCRL. The bug is marked RESOLVED with resolution FIXED.
- Cisco’s leaked private key certificate was revoked for key compromise and reported for CA Program handling.
- The revoked certificate was added to OneCRL.
- Mozilla representative — Reported that Cisco leaked a private key for a certificate, noted it was revoked, and suggested adding it to OneCRL while sharing serial number and DNS name details.
- Mozilla representative — Suggested revoking by subject/public key because private key disclosure was the particularly bad aspect.
- Mozilla representative — Asked whether the CRL was updated, whether a specific CRL URL was correct, and requested the PEM of the certificate.
- Quovadis representative — Confirmed the certificate serial was revoked for Key Compromise and provided the issuing CA CRL URL.
- Mozilla representative — Confirmed the certificate was added to OneCRL.