← DigiCert cases
Bugzilla #1624504
Self Reported Incident
QuoVadis: Failure to revoke certificates with compromised private keys
RESOLVED
FIXED
DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
QuoVadis disclosed a failure to revoke certificates that were found to have compromised private keys. The issue was first reported via email by a third party on March 20, 2020, prompting QuoVadis to investigate and revoke the affected certificates within the required timeframe. Following the incident, QuoVadis implemented improvements to their certificate management system, including the ability to search by SPKI and the establishment of a central blocklist for compromised keys. The case has been resolved, with QuoVadis confirming the successful implementation of these measures.
Chronology
- QuoVadis received a report of compromised private keys associated with their certificates.
- QuoVadis revoked the affected certificates.
- QuoVadis confirmed the implementation of SPKI searching and rejection of CSRs with compromised keys.
- QuoVadis implemented the ability to check and contribute to DigiCert's central blocklist of compromised keys.
Thread Activity
- DigiCert — QuoVadis acknowledged the problem report and committed to investigating and revoking affected certificates.
- DigiCert — Updates on the implementation of SPKI searching and plans for a key blacklist were discussed.
- DigiCert — QuoVadis confirmed the implementation of the central blocklist for compromised keys.
Participants
DigiCert
Community commenter
External References
Similar Local Cases
QuoVadis: OCSP handling of Certificate Transparency Pre-certs
QuoVadis: EV JOI Issue
QuoVadis: hostnames not in preferred name syntax
QuoVadis: Incorrect OCSP Delegated Responder Certificate
QuoVadis: failure to reply to CPR in a timely manner
DigiCert: Issuance of Cert with Compromised Key
QuoVadis: Incorrect EV businessCategory
Sectigo: EV SSL Certificates with incorrect subject details.