← DigiCert cases
Bugzilla #1484798
Ca Security Vulnerability
Revocation Issue
DigiCert: *.sslsimplified.com compromised private key
RESOLVED
FIXED
DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
The case concerns a reported compromise of a private key associated with certificates for *.sslsimplified.com. The initial report was made by Hanno Böck, who reported the key compromise and that DigiCert confirmed it and revoked the certificate. The reporter requested that the issue be added to OneCRL. In the thread, DigiCert confirmed the certificate revocation and the certificate was subsequently added to OneCRL. The bug is marked RESOLVED with resolution FIXED. The thread includes references to certificate details and related discussion links.
Chronology
- Hanno Böck reported a private key compromise for a DigiCert certificate covering *.sslsimplified.com, and DigiCert confirmed the compromise and revoked the certificate.
- The revoked certificate was added to OneCRL.
Thread Activity
- Fastly representative — Wayne Thayer stated that Hanno Böck reported the key compromise, DigiCert confirmed it and revoked the certificate, and that it should be added to OneCRL.
- Fastly representative — Wayne Thayer said the certificate had been added to OneCRL.
Participants
Fastly representative
Community commenter
External References
Similar Local Cases
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
DigiCert: inconsistent revocation / OCSP / CRL behavior
DigiCert: Inconsistent EV audits
Add revoked certificate Certification Authority of WoSign G2 issued by Certum CA root to OneCRL
DigiCert: Issuance of certs with weak keys (ROCA)
DigiCert: Incorrect OCSP Delegated Responder Certificate
DigiCert: Private Keys Disclosed by Customers as Part of CSR
DigiCert: Org information issue in new validation workflow