← DigiCert cases
Bugzilla #1675684 Certificate Problem Report

DigiCert: Private Keys Disclosed by Customers as Part of CSR

RESOLVED DigiCert
AI Summary

DigiCert experienced a security incident where customers inadvertently submitted private keys along with Certificate Signing Requests (CSRs). The issue was identified following a similar report from Entrust, prompting DigiCert to investigate and implement a patch to prevent such submissions. A tool was developed to scan for previously submitted private keys, resulting in the revocation of 337 certificates. The incident has been resolved with improved input validation measures in place.

Model: gpt-4o-mini Generated: 2026-06-13 11:39 UTC Confidence: 0.95
Chronology
  1. Investigation initiated after Entrust's report.
  2. Patch deployed to reject potential private key submissions.
  3. Scanning for private keys completed; revocation of affected certificates.
  4. Case deemed ready for closure.
Participants
Jeremy Rowley B Wilson
Similar Local Cases
#1824206 RESOLVED Certificate Problem Report Opened 2023-03-23 · Closed 2023-04-07 · 68% similar
DigiCert: Inconsistent validation information
#1794050 RESOLVED Certificate Problem Report Opened 2022-10-06 · Closed 2023-02-22 · 67% similar
DigiCert: Org information issue in new validation workflow
#1647084 RESOLVED Certificate Problem Report Opened 2020-06-20 · Closed 2023-02-22 · 64% similar
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
#1653475 RESOLVED Certificate Problem Report Opened 2020-07-17 · Closed 2023-02-22 · 60% similar
DigiCert: Key Size Not Divisible By 8
#1639802 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 59% similar
DigiCert: Failure to revoke key-compromised certificate
#1624527 RESOLVED Certificate Problem Report Opened 2020-03-24 · Closed 2023-02-22 · 59% similar
DigiCert: Issuance of Cert with Compromised Key
#1576013 RESOLVED Certificate Problem Report Opened 2019-08-23 · Closed 2023-02-22 · 59% similar
DigiCert: JOI Issue
#1838334 RESOLVED Certificate Problem Report Opened 2023-06-13 · Closed 2023-06-26 · 58% similar
DigiCert: Sub CA with EV OIDs without audit report

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action