← DigiCert cases
Bugzilla #1653475 Delayed Revocation

DigiCert: Key Size Not Divisible By 8

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert reported a compliance issue involving RSA keys whose key sizes were not divisible by 8. DigiCert said it became aware of the problem after reading a DFN-PKI Bugzilla report (Bug 1651132) and then running its own compliance analytics scan, which found roughly 290 certificates across various CAs with bad key sizes that had not been revoked; DigiCert identified 24 such certificates, with 22 already revoked. DigiCert stated that the remaining two certificates were discovered during a later scan and were scheduled to be revoked within the five-day timeline, and that the last two were logged to CCADB and revoked. DigiCert also described implementing a CA-side block for RSA keys not divisible by 8 starting in Feb 2019 and said it would not issue new certificates in scope of this bug. Mozilla indicated it would close the bug on or about 28-July-2020 unless further issues or questions were raised. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 11:39 UTC Revised: 2026-06-16 19:04 UTC Confidence: 0.50 4 comments
Chronology
  1. DigiCert implemented code blocking RSA keys not divisible by 8 at the CA.
  2. DigiCert scanned its issued certificates and identified DigiCert certificates with key sizes not divisible by 8.
  3. DigiCert revoked 22 certificates identified as affected.
  4. DigiCert found two additional affected certificates and scheduled their revocation.
  5. DigiCert confirmed the last two certificates were logged to CCADB and revoked.
Thread Activity
  1. DigiCert — DigiCert explained it scanned after reading Bug 1651132, found 24 affected DigiCert certificates (22 already revoked), and said the last two would be revoked within the five-day timeline.
  2. DigiCert — DigiCert confirmed the last two certificates were logged to CCADB and revoked, and asked if anything was needed before closing the bug.
  3. Mozilla representative — Mozilla stated it would schedule the bug for closure on or about 28-July-2020 unless further issues or questions were raised.
  4. Community commenter — Ryan Sleevi expressed concern about the explanation for missing past controls and asked for careful examination of past incidents, while noting closure as-is might be acceptable.
Participants
DigiCert Mozilla representative Community commenter
Related Bugzilla IDs Mentioned
Similar Local Cases
#1639801 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 100% similar
DigiCert: Failure to revoke key-compromised certificates within 24 hours
#1640805 RESOLVED Delayed Revocation Opened 2020-05-26 · Closed 2023-02-22 · 100% similar
DigiCert: delayed publication of revocation information
#1651828 RESOLVED Delayed Revocation Opened 2020-07-09 · Closed 2023-02-22 · 100% similar
DigiCert: Delay of revocation for EV audit inconsistency incident
#1797165 RESOLVED Delayed Revocation Opened 2022-10-24 · Closed 2023-02-22 · 99% similar
DigiCert: Delayed Revocation of ~5.5 hours
#1693343 RESOLVED Delayed Revocation Opened 2021-02-17 · Closed 2023-02-22 · 98% similar
DigiCert: Failure to find and revoke key-compromised certificates within 24 hours
#1516599 RESOLVED Delayed Revocation Opened 2018-12-28 · Closed 2023-02-22 · 97% similar
DigiCert: Underscores - Ericsson
#1516453 RESOLVED Delayed Revocation Opened 2018-12-26 · Closed 2023-02-22 · 96% similar
DigiCert: Underscores - Discover
#1516561 RESOLVED Delayed Revocation Opened 2018-12-27 · Closed 2023-02-22 · 96% similar
DigiCert: Underscores - Canadian Imperial Bank of Commerce

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action