← DigiCert cases
Bugzilla #1624504 Self Reported Incident

QuoVadis: Failure to revoke certificates with compromised private keys

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

QuoVadis disclosed a failure to revoke certificates that were found to have compromised private keys. The issue was first reported via email by a third party on March 20, 2020, prompting QuoVadis to investigate and revoke the affected certificates within the required timeframe. Following the incident, QuoVadis implemented improvements to their certificate management system, including the ability to search by SPKI and the establishment of a central blocklist for compromised keys. The case has been resolved, with QuoVadis confirming the successful implementation of these measures.

Model: gpt-4o-mini Generated: 2026-06-13 21:19 UTC Revised: 2026-06-16 18:48 UTC Confidence: 0.85 14 comments
Chronology
  1. QuoVadis received a report of compromised private keys associated with their certificates.
  2. QuoVadis revoked the affected certificates.
  3. QuoVadis confirmed the implementation of SPKI searching and rejection of CSRs with compromised keys.
  4. QuoVadis implemented the ability to check and contribute to DigiCert's central blocklist of compromised keys.
Thread Activity
  1. DigiCert — QuoVadis acknowledged the problem report and committed to investigating and revoking affected certificates.
  2. DigiCert — Updates on the implementation of SPKI searching and plans for a key blacklist were discussed.
  3. DigiCert — QuoVadis confirmed the implementation of the central blocklist for compromised keys.
Participants
DigiCert Community commenter
External References
Similar Local Cases
#1579950 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-09 · Closed 2022-11-14 · 95% similar
QuoVadis: OCSP handling of Certificate Transparency Pre-certs
#1581234 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-13 · Closed 2023-02-22 · 95% similar
QuoVadis: EV JOI Issue
#1738472 RESOLVED Self Reported Incident Opened 2021-10-29 · Closed 2023-02-22 · 87% similar
QuoVadis: hostnames not in preferred name syntax
#1649938 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 85% similar
QuoVadis: Incorrect OCSP Delegated Responder Certificate
#1590171 RESOLVED Self Reported Incident Opened 2019-10-21 · Closed 2024-06-30 · 82% similar
QuoVadis: failure to reply to CPR in a timely manner
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 77% similar
DigiCert: Issuance of Cert with Compromised Key
#1593357 RESOLVED Self Reported Incident Opened 2019-11-01 · Closed 2023-02-22 · 76% similar
QuoVadis: Incorrect EV businessCategory
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 76% similar
Sectigo: EV SSL Certificates with incorrect subject details.

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action