← D-TRUST cases
Bugzilla #1682270 Ca Certificate Compliance Incident Closure Request

D-TRUST: Private Key Disclosed by Customer as Part of CSR

RESOLVED FIXED D-TRUST
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

D-TRUST reported that, during its certificate application process, a customer could potentially submit a private key as part of a CSR via the application processing interface. D-TRUST initiated an internal investigation on 2020-11-24 after reviewing published Mozilla Bugzilla incidents involving Entrust and DigiCert. The investigation found no evidence that a private key was provided for a currently valid certificate, but it identified that in the past a private key had been provided at the end of a CSR; the affected certificate was revoked shortly after issuance. D-TRUST stated it installed a bug fix to prevent issuing certificates where the private key is provided with the CSR, and that only correct CSRs are accepted going forward. It also stated that if a CSR is incorrect or includes additions, it will be rejected with an error message and the CSR/private key will not be saved. Mozilla closed the bug as straightforward, with no further discussion expected.

Model: gpt-5.4-nano Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 11:00 UTC Confidence: 0.86 2 comments
Chronology
  1. D-TRUST began an internal investigation into whether private keys could be transmitted during CSR processing.
  2. D-TRUST completed thorough analysis and identified a revoked certificate associated with a CSR that included a private key.
  3. D-TRUST completed installation, testing, and final approval of the bug fix to prevent private keys being submitted with CSRs.
Thread Activity
  1. Bdr representative — Enrico Entschew described D-TRUST’s investigation, the finding of a past CSR that included a private key (with the certificate revoked shortly after issuance), and the bug fix to prevent private keys from being submitted/saved with CSRs.
  2. Mozilla representative — Mozilla closed the bug, stating it appeared straightforward and there was nothing more to discuss.
Participants
Bdr representative Mozilla representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1691117 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2021-02-05 · Closed 2023-02-22 · 100% similar
D-TRUST: Certificate with RSA key where modulus is not divisible by 8
#1924385 RESOLVED Ca Certificate Compliance Revocation Issue Closure Request Opened 2024-10-13 · Closed 2025-07-16 · 100% similar
D-Trust: Missed Revocation of TLS certificates affected by Bugzilla 1884714
#1939809 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2025-01-03 · Closed 2026-06-12 · 100% similar
D-Trust: QCStatement with http link of PKI Disclosure Statements
#1610303 RESOLVED Ca Certificate Compliance Opened 2020-01-20 · Closed 2023-02-22 · 96% similar
D-TRUST: Issuance of non-conformant SSL certificate
#1647468 RESOLVED Ca Certificate Compliance Opened 2020-06-22 · Closed 2023-02-22 · 96% similar
D-TRUST: Wrong key usage (Key Encipherment)
#1896190 RESOLVED Ca Certificate Compliance Opened 2024-05-10 · Closed 2024-11-06 · 96% similar
D-Trust: Issuance of an EV certificate containing a mixup of the Subject's postalCode and localityName
#1976837 RESOLVED Incident Opened 2025-07-11 · Closed 2025-08-19 · 87% similar
D-Trust: Defective certificate incident reporting form
#2009149 RESOLVED Incident Opened 2026-01-08 · Closed 2026-04-19 · 87% similar
D-Trust: Expired certificate provided on the CA TLS test website for demonstration of valid certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action