D-TRUST: Private Key Disclosed by Customer as Part of CSR
D-TRUST reported that, during its certificate application process, a customer could potentially submit a private key as part of a CSR via the application processing interface. D-TRUST initiated an internal investigation on 2020-11-24 after reviewing published Mozilla Bugzilla incidents involving Entrust and DigiCert. The investigation found no evidence that a private key was provided for a currently valid certificate, but it identified that in the past a private key had been provided at the end of a CSR; the affected certificate was revoked shortly after issuance. D-TRUST stated it installed a bug fix to prevent issuing certificates where the private key is provided with the CSR, and that only correct CSRs are accepted going forward. It also stated that if a CSR is incorrect or includes additions, it will be rejected with an error message and the CSR/private key will not be saved. Mozilla closed the bug as straightforward, with no further discussion expected.
- D-TRUST began an internal investigation into whether private keys could be transmitted during CSR processing.
- D-TRUST completed thorough analysis and identified a revoked certificate associated with a CSR that included a private key.
- D-TRUST completed installation, testing, and final approval of the bug fix to prevent private keys being submitted with CSRs.
- Bdr representative — Enrico Entschew described D-TRUST’s investigation, the finding of a past CSR that included a private key (with the certificate revoked shortly after issuance), and the bug fix to prevent private keys from being submitted/saved with CSRs.
- Mozilla representative — Mozilla closed the bug, stating it appeared straightforward and there was nothing more to discuss.