← DigiCert cases
Bugzilla #1427034
Certificate Problem Report
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
RESOLVED
DigiCert
AI Summary
A certificate issued by DigiCert for the domain localbattle.net was found to contain an embedded private key, leading to a potential key compromise. This issue was initially reported in relation to Blizzard's battle.net application. After a brief period of using a locally created CA, Blizzard reverted to using a certificate from DigiCert with the same vulnerability. The certificate has since been revoked.
Chronology
- Initial report of key compromise
- DigiCert confirmed revocation of the certificate
- Certificate added to OneCRL
Participants
Hanno Boeck
Kathleen Wilson
Jeremy Rowley
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
DigiCert / InfoCert: Insufficient Serial Number Entropy
DigiCert: ECCE 001 issuing certificates without subject alternative name extension
DigiCert: Non-BR Compliant Certificates - missing CP/CPS OID
DigiCert: no subject alternative name in Siemens certs
Microsoft DSRE PKI: Microsoft shares wildcard certificates among cloud instances
DigiCert: Microsoft: Incident report for Microsoft Dynamics incident
DigiCert: Non-BR-Compliant OCSP Responders
DigiCert / CTJ: Metadata in OU fields, Reserved IP Address