← DigiCert cases
Bugzilla #1427034 Ca Security Vulnerability Security Incident

DigiCert: localbattle.net certificate with embedded private key (key compromise)

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened by an external reporter who stated that Blizzard’s battle.net application contained a certificate and embedded private key for the domain localbattle.net that pointed to localhost, which they characterized as a key compromise. The reporter said Blizzard had previously used a locally created CA for a few days, but then returned to issuing a certificate with an embedded private key from Digicert. The reporter asked Digicert to consider the report as a key compromise and noted it had been reported to the public mailing list. A Fastly participant asked whether the certificate should be added to OneCRL, and Digicert’s Jeremy Rowley stated that the certificate was revoked and that Digicert revokes all certificates within 24 hours of confirming key compromise when it is reported to r**********e@digicert.com. Another participant requested adding the certificate to OneCRL, and the reporter later confirmed it was added. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 11:18 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.90 6 comments
Chronology
  1. A certificate for localbattle.net with an embedded private key was reported as a key compromise and submitted for CT lookup.
  2. Digicert revoked the reported certificate after confirming the key compromise.
  3. The certificate was added to OneCRL.
Thread Activity
  1. Hboeck representative — Reported that a localbattle.net certificate with an embedded private key was issued by Digicert and asked Digicert to treat it as a key compromise.
  2. Hboeck representative — Submitted the certificate to CT and shared the crt.sh link.
  3. Fastly representative — Asked whether the certificate should be added to OneCRL.
  4. DigiCert — Stated the certificate was revoked and noted key-compromise reports should go to r**********e@digicert.com for 24-hour revocation handling.
  5. Fastly representative — Requested adding the certificate to OneCRL.
  6. Mozilla representative — Confirmed the certificate was added to OneCRL.
Participants
Hboeck representative Mozilla representative Fastly representative DigiCert
Related Bugzilla IDs Mentioned
Similar Local Cases
#1484798 RESOLVED Ca Security Vulnerability Revocation Issue Opened 2018-08-20 · Closed 2024-05-09 · 93% similar
DigiCert: *.sslsimplified.com compromised private key
#1675684 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-11-06 · Closed 2023-02-22 · 78% similar
DigiCert: Private Keys Disclosed by Customers as Part of CSR
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 78% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 77% similar
DigiCert: OCSP responder returning invalid responses
#1577014 RESOLVED Security Incident Opened 2019-08-27 · Closed 2023-02-22 · 75% similar
DigiCert: OCSP services returns 1 byte
#1820269 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-03-03 · Closed 2024-06-30 · 69% similar
DigiCert: 4 CRLs unavailable or not responding
#1398269 RESOLVED Certificate Misissuance Opened 2017-09-08 · Closed 2023-02-22 · 69% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1816806 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-02-15 · Closed 2023-03-09 · 68% similar
DigiCert: OCSP not responding issue

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action