← DigiCert cases
Bugzilla #1675684 Ca Security Vulnerability Security Incident

DigiCert: Private keys disclosed by customers via CSR appended data

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case describes a DigiCert enrollment-system issue where customers could append information to the end of a CSR, and that appended information was dropped during certificate enrollment but still sent to DigiCert servers. DigiCert reported that the appended information could include a private key copied and pasted by the customer along with the CSR, which would compromise the private key. DigiCert stated it patched its TLS system to prevent inclusion of appended information outside of the CSR and built tools to detect private-key submissions. DigiCert then scanned its database for private keys submitted after CSRs, identified certificates corresponding to those keys, and revoked those certificates. DigiCert also posted CSRs created using the compromised keys so other CAs could block the keys as well. The bug was marked FIXED and DigiCert indicated it was ready to close, with Mozilla stating it would close unless additional concerns were raised.

Model: gpt-5.4-nano Generated: 2026-06-13 11:39 UTC Revised: 2026-06-16 19:05 UTC Confidence: 0.86 6 comments
Chronology
  1. DigiCert deployed a patch to reject information that could be a private key submitted outside the CSR.
  2. DigiCert finished scanning for private keys in its enrollment database and revoked certificates whose public keys matched submitted private keys.
  3. DigiCert posted CSRs created using the compromised keys for other CAs to block.
Thread Activity
  1. DigiCert — Explained how appended CSR data could include a customer private key, described the TLS patch to prevent extra appended data, and outlined plans to scan and revoke affected certificates.
  2. DigiCert — Reported that the tool to find these keys was finished and that scanning was underway.
  3. DigiCert — Reported scan results: 337 keys submitted by customers after the CSR, with corresponding certificates identified and revoked, and CSRs posted for other CAs.
  4. DigiCert — Provided a formatted incident report including investigation timeline, confirmation of the issue, deployment of the patch, completion of scanning and revocation, and steps to prevent recurrence.
  5. DigiCert — Said the case was ready to close.
  6. Mozilla representative — Indicated Mozilla would close the bug the following week unless there were additional concerns.
Participants
DigiCert Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1662346 RESOLVED Ca Security Vulnerability Security Incident Opened 2020-09-01 · Closed 2023-02-22 · 100% similar
DigiCert: OCSP responder returning invalid responses
#1744795 RESOLVED Ca Security Vulnerability Security Incident Opened 2021-12-07 · Closed 2023-02-22 · 100% similar
DigiCert: Issuance of certs with weak keys (ROCA)
#1816806 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-02-15 · Closed 2023-03-09 · 98% similar
DigiCert: OCSP not responding issue
#1820269 RESOLVED Ca Security Vulnerability Security Incident Opened 2023-03-03 · Closed 2024-06-30 · 88% similar
DigiCert: 4 CRLs unavailable or not responding
#1577014 RESOLVED Security Incident Opened 2019-08-27 · Closed 2023-02-22 · 87% similar
DigiCert: OCSP services returns 1 byte
#1427034 RESOLVED Ca Security Vulnerability Security Incident Opened 2017-12-25 · Closed 2024-05-09 · 78% similar
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
#1878106 RESOLVED Ca Security Vulnerability Security Incident Opened 2024-02-01 · Closed 2024-03-08 · 77% similar
HARICA: Anomaly in OCSP services after CA software upgrade
#1424305 RESOLVED Ca Security Vulnerability Incident Opened 2017-12-08 · Closed 2023-02-22 · 77% similar
DigiCert: Microsoft: Incident report for Microsoft Dynamics incident

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action