DigiCert: Private keys disclosed by customers via CSR appended data
This case describes a DigiCert enrollment-system issue where customers could append information to the end of a CSR, and that appended information was dropped during certificate enrollment but still sent to DigiCert servers. DigiCert reported that the appended information could include a private key copied and pasted by the customer along with the CSR, which would compromise the private key. DigiCert stated it patched its TLS system to prevent inclusion of appended information outside of the CSR and built tools to detect private-key submissions. DigiCert then scanned its database for private keys submitted after CSRs, identified certificates corresponding to those keys, and revoked those certificates. DigiCert also posted CSRs created using the compromised keys so other CAs could block the keys as well. The bug was marked FIXED and DigiCert indicated it was ready to close, with Mozilla stating it would close unless additional concerns were raised.
- DigiCert deployed a patch to reject information that could be a private key submitted outside the CSR.
- DigiCert finished scanning for private keys in its enrollment database and revoked certificates whose public keys matched submitted private keys.
- DigiCert posted CSRs created using the compromised keys for other CAs to block.
- DigiCert — Explained how appended CSR data could include a customer private key, described the TLS patch to prevent extra appended data, and outlined plans to scan and revoke affected certificates.
- DigiCert — Reported that the tool to find these keys was finished and that scanning was underway.
- DigiCert — Reported scan results: 337 keys submitted by customers after the CSR, with corresponding certificates identified and revoked, and CSRs posted for other CAs.
- DigiCert — Provided a formatted incident report including investigation timeline, confirmation of the issue, deployment of the patch, completion of scanning and revocation, and steps to prevent recurrence.
- DigiCert — Said the case was ready to close.
- Mozilla representative — Indicated Mozilla would close the bug the following week unless there were additional concerns.