← DigiCert cases
Bugzilla #1624527 Certificate Problem Report

DigiCert: Issuance of Cert with Compromised Key

RESOLVED DigiCert
AI Summary

DigiCert reported the issuance of certificates with a compromised key due to a bug in their validation process. The issue was discovered during an escape analysis after a SEV1 incident, leading to the mis-issuance of 123 OV and 36 EV certificates. DigiCert took immediate action to revoke the affected certificates and implemented a blacklist system to prevent future occurrences. The case has been resolved with the implementation of new processes to enhance certificate issuance security.

Model: gpt-4o-mini Generated: 2026-06-13 11:36 UTC Confidence: 0.95
Chronology
  1. SEV1 outage reported for storefront.
  2. Problem discovered during escape analysis.
  3. All impacted certificates revoked.
  4. Key blocklist tool went live.
Participants
Jeremy Rowley Wayne Thayer Ryan Sleevi
External References
Similar Local Cases
#1304895 RESOLVED Certificate Problem Report Opened 2016-09-22 · Closed 2023-02-22 · 77% similar
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
#1550645 RESOLVED Certificate Problem Report Opened 2019-05-10 · Closed 2023-02-22 · 76% similar
DigiCert: CAA Checking Issue
#1639802 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 71% similar
DigiCert: Failure to revoke key-compromised certificate
#1576013 RESOLVED Certificate Problem Report Opened 2019-08-23 · Closed 2023-02-22 · 70% similar
DigiCert: JOI Issue
#1662346 RESOLVED Certificate Problem Report Opened 2020-09-01 · Closed 2023-02-22 · 69% similar
DigiCert: OCSP responder returning invalid responses
#1639801 RESOLVED Certificate Problem Report Opened 2020-05-21 · Closed 2023-02-22 · 69% similar
DigiCert: Failure to revoke key-compromised certificates within 24 hours
#1593814 RESOLVED Certificate Problem Report Opened 2019-11-04 · Closed 2023-02-22 · 69% similar
DigiCert: & character in a printableString in ICA
#1397951 RESOLVED Certificate Problem Report Opened 2017-09-07 · Closed 2023-02-22 · 69% similar
DigiCert / InfoCert: Insufficient Serial Number Entropy

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action