← Sectigo cases
Bugzilla #1699756
Self Reported Incident
Sectigo: Reseller ZeroSSL and Private Key Generation
RESOLVED
INVALID
Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves Sectigo's reseller, ZeroSSL, and concerns the generation and storage of private keys for SSL certificates. The issue was raised regarding whether ZeroSSL's practices violated Mozilla's Root Store Policy, specifically around the generation and storage of private keys. After discussions and clarifications from ZeroSSL, it was established that private keys are generated client-side and stored securely. The Mozilla representative, Ben Wilson, ultimately concluded that the process does not expose private keys in a way that violates policy, leading to the bug being closed as invalid.
Chronology
- Initial concerns raised about ZeroSSL's private key generation and storage practices.
- Bug closed as invalid after confirming no policy violation.
Thread Activity
- Mozilla representative — Raised concerns about ZeroSSL's private key generation process potentially violating Mozilla's Root Store Policy.
- Sectigo — Defended ZeroSSL's practices, stating they do not generate keys and thus do not violate policy.
- Mozilla representative — Concluded that ZeroSSL's key generation process does not present an issue and closed the bug.
Participants
Mozilla representative
Sectigo
Stack representative
Thisisntrocket representative
External References
Similar Local Cases
Sectigo: Failure to provide timely incident reports
Sectigo: Non-revocation of certificates with subject:organizationalUnitName in DV certificates
Sectigo: CPR response issues
Sectigo: DCV Reuse after 825 days
Sectigo: Failure to block disallowed LDH labels in domain names
Sectigo: Subject field with unvalidated information included in certificates
Sectigo: Incorrect JOI for federal credit unions
Sectigo: 2020 failure to respond to CPRs discovered