← OneCRL Browser

OneCRL Entry

514b3b98-0554-4aff-b117-faeafe5f4897

Revocation Entry

Status
enabled
Serial
00C37A887B4E832EBC401BB791789A15CF
Last Modified
2018-08-29 17:46:12 UTC
Schema
1552492994435

Issuer

DN
C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Organization Validation Secure Server CA
DN SHA-256
4767ac526dc7881aad9f1fa18669e6226b6a94aaa3b5f5e92fc06fb632e8c9ee
Issuer DER
MIGWMQswCQYDVQQGEwJHQjEbMBkGA1UECBMSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYDVQQHEwdTYWxmb3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRlZDE8MDoGA1UEAxMzQ09NT0RPIFJTQSBPcmdhbml6YXRpb24gVmFsaWRhdGlvbiBTZWN1cmUgU2VydmVyIENB

Context

Bugzilla
1480853
Action
Two certificates were added to OneCRL by w**********r@mozilla.com on 2018-08-29 17:32:10Z and 2018-08-29 17:33:12Z; both entries were enabled and marked key compromise.
Confidence
Explicit in OneCRL thread · 0.96

AI Summary

Generated 2026-06-30 11:09 UTC · Model: gpt-5.4-mini

Wayne Thayer opened this CA Program bug on 2018-08-03 after reporting that the private key for a certificate used by localhost.megasyncloopback.mega.nz was embedded in client software. He initially asked that the referenced certificate be added to OneCRL, and later clarified that the relevant object was a precertificate and identified the corresponding certificate plus a second certificate sharing the same private key. On 2018-08-30 he stated that these certificates had been added to OneCRL. The OneCRL entries show two enabled revocations added by w**********r@mozilla.com on 2018-08-29, both with detail_why set to key compromise. The thread does not state a CCADB revocation field or candidate-report state as the trigger, so that qualification is unknown from the explicit record. The external cause is explicit: a compromised private key reported in Mozilla dev security policy, involving the MEGA-related localhost.megasyncloopback.mega.nz certificate and a second Comodo-signed certificate using the same key.

OneCRL action

Two certificates were added to OneCRL by w**********r@mozilla.com on 2018-08-29 17:32:10Z and 2018-08-29 17:33:12Z; both entries were enabled and marked key compromise.

CCADB trigger

Unknown / not stated; OneCRL entries only show detail_why=key compromise, with no explicit CCADB revocation field or candidate-report state cited.

External cause

Compromised private key for localhost.megasyncloopback.mega.nz reported in Mozilla dev security policy; a second certificate sharing the same private key was also identified. No CA closure is stated.

Confidence

Explicit in OneCRL thread · 0.96

Chronology
  • 2018-08-03Bug 1480853 opened reporting a compromised private key and requesting OneCRL addition.
  • 2018-08-06Wayne Thayer clarified the original reference was a precertificate and identified the corresponding certificate plus a second certificate sharing the same private key.
  • 2018-08-29Two OneCRL entries were created by w**********r@mozilla.com with detail_why set to key compromise.
  • 2018-08-30Wayne Thayer stated that the certificates had been added to OneCRL.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1552492994435,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1480853",
        "who": "wthayer@mozilla.com",
        "why": "key compromise",
        "name": "",
        "created": "2018-08-29T17:32:10Z"
    },
    "enabled": true,
    "issuerName": "MIGWMQswCQYDVQQGEwJHQjEbMBkGA1UECBMSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYDVQQHEwdTYWxmb3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRlZDE8MDoGA1UEAxMzQ09NT0RPIFJTQSBPcmdhbml6YXRpb24gVmFsaWRhdGlvbiBTZWN1cmUgU2VydmVyIENB",
    "serialNumber": "AMN6iHtOgy68QBu3kXiaFc8=",
    "id": "514b3b98-0554-4aff-b117-faeafe5f4897",
    "last_modified": 1535564772273
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action