← D-TRUST cases
Bugzilla #1682270 Ca Certificate Compliance Incident Closure Request

D-TRUST: Private Key Disclosed by Customer as Part of CSR

RESOLVED FIXED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-TRUST reported that, during its certificate application process, a customer could potentially submit a private key as part of a CSR via the application processing interface. D-TRUST initiated an internal investigation on 2020-11-24 after reviewing published Mozilla Bugzilla incidents involving Entrust and DigiCert. The investigation found no evidence that a private key was provided for a currently valid certificate, but it identified that in the past a private key had been provided at the end of a CSR; the affected certificate was revoked shortly after issuance. D-TRUST stated it installed a bug fix to prevent issuing certificates where the private key is provided with the CSR, and that only correct CSRs are accepted going forward. It also stated that if a CSR is incorrect or includes additions, it will be rejected with an error message and the CSR/private key will not be saved. Mozilla closed the bug as straightforward, with no further discussion expected.

Model: gpt-5.4-nano Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 11:00 UTC Confidence: 0.86 2 comments
Chronology
  1. D-TRUST began an internal investigation into whether private keys could be transmitted during CSR processing.
  2. D-TRUST completed thorough analysis and identified a revoked certificate associated with a CSR that included a private key.
  3. D-TRUST completed installation, testing, and final approval of the bug fix to prevent private keys being submitted with CSRs.
Thread Activity
  1. Bdr representative — Enrico Entschew described D-TRUST’s investigation, the finding of a past CSR that included a private key (with the certificate revoked shortly after issuance), and the bug fix to prevent private keys from being submitted/saved with CSRs.
  2. Mozilla representative — Mozilla closed the bug, stating it appeared straightforward and there was nothing more to discuss.
Participants
Bdr representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1691117 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2021-02-05 · Closed 2023-02-22 · 100% similar
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 100% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1939809 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-01-03 · Closed 2026-06-12 · 100% similar
D-Trust: QCStatement with http link of PKI Disclosure Statements
#1610303 RESOLVED Ca Certificate Compliance Opened 2020-01-20 · Closed 2023-02-22 · 96% similar
D-TRUST: Issuance of non-conformant SSL certificate
#1647468 RESOLVED Ca Certificate Compliance Opened 2020-06-22 · Closed 2023-02-22 · 96% similar
D-TRUST: Wrong key usage (Key Encipherment)
#1896190 RESOLVED Ca Certificate Compliance Opened 2024-05-10 · Closed 2024-11-06 · 96% similar
D-Trust: Issuance of an EV certificate containing a mixup of the Subject's postalCode and localityName
#2029013 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Validation Issue Opened 2026-04-02 Still Open · 95% similar
D-Trust: Missing Pre-Signing Linting for TLS Issuance
#1976837 RESOLVED Incident Opened 2025-07-11 · Closed 2025-08-19 · 87% similar
D-Trust: Defective certificate incident reporting form

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action