DigiCert: Failure to find and revoke key-compromised certificates within 24 hours
Rob Stradling reported that DigiCert’s key-compromise reporting tool accepted evidence but did not revoke certificates within the 24-hour requirement. In the bug, Rob stated that after submitting multiple private keys/CSRs, DigiCert’s automated response indicated that no matching certificates were found and that the submitted keys were not revoked. DigiCert investigated and said the issue began after a CA migration to a new data center on Feb 6, 2021, when configuration variables were not updated, causing a connectivity issue between the CA and the revocation service. DigiCert corrected the URL on Feb 18, 2021, identified certificates that should have been revoked, and revoked eight associated certificates. DigiCert also added alerts for connectivity issues and described additional remediation work, including CPS updates and improvements to health checks, queuing, logging, and notifications for the key-compromise workflow. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it would be closed on or about 19-March-2021.
- DigiCert migrated its CA to a new data center, and configuration variables for the revocation-related service were not updated.
- Rob reported that key-compromise submissions were not resulting in certificate revocation within 24 hours.
- DigiCert corrected the connectivity issue, identified affected certificates, and revoked eight certificates.
- DigiCert deployed code changes and updated its CPS with the service instructions.
- Mozilla scheduled the bug to be closed on or about 19-March-2021.
- Sectigo — Rob reported that DigiCert’s compromised key service returned case emails saying no matching certificates were found and that revocation did not occur within 24 hours.
- DigiCert — Jeremy asked Rob to send the CSR that Rob had submitted.
- Sectigo — Rob replied that he emailed r**********e@digicert.com with case numbers for investigation.
- DigiCert — Jeremy said they discovered the issue and would post a preliminary incident report.
- DigiCert — Jeremy provided an incident report describing the migration-related connectivity failure, the corrective actions, and the revocation of eight certificates.
- Sectigo — Rob confirmed the compromised key reporting tool appeared fixed after submitting another key and receiving an automated response indicating expected revocation behavior.
- DigiCert — Jeremy described CPS update work and additional remediation (health checks, queuing, logging/notifications) and stated a deployment timeline.
- DigiCert — Jeremy stated the code changes were deployed and the CPS was updated with the service instructions.
- Mozilla representative — Mozilla said it would schedule the bug to be closed on or about 19-March-2021.