← DigiCert cases
Bugzilla #1639802
Certificate Problem Report
DigiCert: Failure to revoke key-compromised certificate
RESOLVED
DigiCert
AI Summary
This case addresses DigiCert's failure to revoke a certificate after a key compromise was reported. A certificate problem report was submitted on May 8, 2020, indicating that a private key had been compromised. Although some certificates were revoked within 24 hours, others remained valid due to inadequate response procedures. The issue was ultimately resolved with the implementation of longer-term mitigations to prevent future occurrences.
Chronology
- Certificate problem report submitted regarding key compromise.
- Bug reported and discussed in Bugzilla.
- Tracking implementation of blacklist key checker.
- Case marked as resolved.
Participants
Brenda Bernal
Matt Palmer
Jeremy Rowley
Ryan Sleevi
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
DigiCert: Failure to revoke key-compromised certificates within 24 hours
DigiCert: Failure to disclose Unconstrained Intermediate within 7 Days
DigiCert: SHA-256 hash algorithm used with ECC P-384 key
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
DigiCert: CAA Checking Issue
DigiCert: delayed publication of revocation information
DigiCert: Underscores - Citi
DigiCert: Underscores - Ericsson