← D-TRUST cases
Bugzilla #1682270 Certificate Problem Report

D-TRUST: Private Key Disclosed by Customer as Part of CSR

RESOLVED FIXED D-TRUST
AI Summary

D-TRUST identified a vulnerability where private keys could be inadvertently submitted during the certificate signing request (CSR) process. An internal investigation revealed that a private key was submitted with a CSR for a certificate that was later revoked. D-TRUST has since implemented a bug fix to prevent such occurrences by rejecting incorrect CSRs. The issue was resolved on December 14, 2020, and only one certificate was affected, issued on July 2, 2020.

Model: gpt-4o-mini Generated: 2026-06-13 21:21 UTC Confidence: 1.00
Chronology
  1. Investigation initiated after potential vulnerability identified.
  2. Thorough analysis revealed a revoked certificate with a private key submission.
  3. Bug fix successfully completed and approved.
Participants
Enrico Entschew bwilson@mozilla.com
Similar Local Cases
#1610303 RESOLVED Certificate Problem Report Opened 2020-01-20 · Closed 2023-02-22 · 66% similar
D-TRUST: Issuance of non-conformant SSL certificate
#1896190 RESOLVED Certificate Problem Report Opened 2024-05-10 · Closed 2024-11-06 · 61% similar
D-Trust: Issuance of an EV certificate containing a mixup of the Subject's postalCode and localityName
#1599561 RESOLVED Certificate Problem Report Opened 2019-11-26 · Closed 2023-02-22 · 61% similar
D-TRUST: EV certificates with incorrectly used businessCategory entry
#2029013 ASSIGNED Certificate Problem Report Opened 2026-04-02 Still Open · 60% similar
D-Trust: Missing Pre-Signing Linting for TLS Issuance
#2009149 RESOLVED Certificate Problem Report Opened 2026-01-08 · Closed 2026-04-19 · 60% similar
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates
#1939809 RESOLVED Certificate Problem Report Opened 2025-01-03 · Closed 2025-03-21 · 60% similar
D-Trust: QCStatement with http link of PKI Disclosure Statements
#1924385 RESOLVED Certificate Problem Report Opened 2024-10-13 · Closed 2025-07-16 · 60% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1893610 RESOLVED Certificate Problem Report Opened 2024-04-26 · Closed 2024-06-30 · 60% similar
D-Trust: Notice to affected Subscriber and person filing CPR not sent within 24 hours

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action