DigiCert: localbattle.net certificate with embedded private key (key compromise)
The bug was opened by an external reporter who stated that Blizzard’s battle.net application contained a certificate and embedded private key for the domain localbattle.net that pointed to localhost, which they characterized as a key compromise. The reporter said Blizzard had previously used a locally created CA for a few days, but then returned to issuing a certificate with an embedded private key from Digicert. The reporter asked Digicert to consider the report as a key compromise and noted it had been reported to the public mailing list. A Fastly participant asked whether the certificate should be added to OneCRL, and Digicert’s Jeremy Rowley stated that the certificate was revoked and that Digicert revokes all certificates within 24 hours of confirming key compromise when it is reported to r**********e@digicert.com. Another participant requested adding the certificate to OneCRL, and the reporter later confirmed it was added. The bug is marked RESOLVED with resolution FIXED.
- A certificate for localbattle.net with an embedded private key was reported as a key compromise and submitted for CT lookup.
- Digicert revoked the reported certificate after confirming the key compromise.
- The certificate was added to OneCRL.
- Hboeck representative — Reported that a localbattle.net certificate with an embedded private key was issued by Digicert and asked Digicert to treat it as a key compromise.
- Hboeck representative — Submitted the certificate to CT and shared the crt.sh link.
- Fastly representative — Asked whether the certificate should be added to OneCRL.
- DigiCert — Stated the certificate was revoked and noted key-compromise reports should go to r**********e@digicert.com for 24-hour revocation handling.
- Fastly representative — Requested adding the certificate to OneCRL.
- Mozilla representative — Confirmed the certificate was added to OneCRL.