DigiCert: Failure to revoke key-compromised certificate
This case involves DigiCert's failure to revoke a certificate associated with a compromised private key within the required timeframe. A certificate problem report was submitted on May 8, 2020, indicating the compromise and requesting revocation of all related certificates. While two certificates were revoked within 24 hours, one certificate remained valid despite the reported compromise. The case highlights issues with DigiCert's revocation processes and the need for improved automation to prevent similar failures in the future. The issue has been marked as resolved after DigiCert implemented both short-term and long-term mitigations.
- Certificate problem report submitted regarding a compromised private key.
- DigiCert acknowledged the failure to revoke one certificate in a timely manner.
- DigiCert planned to roll out a blacklist key checker to improve revocation processes.
- Hezmatt representative — Reported that one certificate remained valid despite the compromise.
- DigiCert — Noted that the issue was similar to another bug and discussed the expected timeframe for remediation.
- Community commenter — Suggested that the case should not be combined with another bug due to distinct failure modes.
- Community commenter — Concluded that the case could be marked as resolved after DigiCert's implementation of mitigations.