← DigiCert cases
Bugzilla #1693343
Certificate Problem Report
DigiCert: Failure to find and revoke key-compromised certificates within 24 hours
RESOLVED
DigiCert
AI Summary
DigiCert faced an issue where key-compromised certificates were not revoked within the mandated 24-hour period. The problem stemmed from a connectivity issue between the CA and the revocation service following a data center migration. After a report from a user, DigiCert identified the issue, corrected the connectivity problem, and successfully revoked the affected certificates. The CA has since implemented measures to prevent similar issues in the future.
Chronology
- DigiCert migrated to a new data center, causing connectivity issues.
- User reported failure to revoke compromised keys.
- DigiCert corrected the URL and revoked the certificates.
- DigiCert deployed code changes and updated CPS.
Participants
Rob Stradling
Jeremy Rowley
External References
Similar Local Cases
Digicert: Preview certificate uploaded to CCADB instead of the actual certificate
DigiCert: SHA-256 hash algorithm used with ECC P-384 key
DigiCert: Failure to revoke key-compromised certificates within 24 hours
DigiCert: Failure to revoke key-compromised certificate
DigiCert: CAA Checking Issue
DigiCert: Key Size Not Divisible By 8
DigiCert: improper use of domain validation method
DigiCert: Issuance of certs with weak keys (ROCA)