← SSL.com cases
Bugzilla #1962800
Certificate Problem Report
SSL.com: Revocation due to keyCompromise while keeping other TLS cert w/ the same pubKey unrevoked
RESOLVED
INVALID
SSL.com
AI Summary
A subscriber of SSL.com revoked their certificate due to a key compromise on February 25th. However, SSL.com did not revoke other TLS certificates that shared the same public key. The expected behavior is to revoke all certificates with the same public key if a key compromise is reported. The case was resolved as invalid, indicating that the revocation request may not have provided sufficient evidence of the key compromise.
Chronology
- Subscriber revoked certificate due to keyCompromise.
- Bug resolved as invalid.
Participants
ragtime_knoll5n@icloud.com
aaron@letsencrypt.org
External References
Similar Local Cases
SSL.com: Delayed revocation of certificate with weak key
SSL.com: DCV bypass and issue fake certificates for any MX hostname
SSL.com: Issuance of 1 EV TLS certificate using a Registration/Incorporation Agency not included in our approved public list.
SSL.com: Expired CRLs
SSL.com: "unknown" OCSP response for issued certificates
SSL.com: CRL not found - SSL.com-Enterprise-Intermediate-EV-RSA-4096-R1.crl
SSL.com: Revocation process requires submission to a form that is unusable
SSL.com: Insufficient serial number entropy