← OneCRL Browser

OneCRL Entry

8a401bee-cee4-40d8-a61e-903ca0cda17f

Revocation Entry

Status
enabled
Serial
2F8D5A9A8087E01D9A8125290FC59DD8
Last Modified
2018-08-29 17:46:12 UTC
Schema
1552492994435

Issuer

DN
C=US, O=GeoTrust Inc., CN=RapidSSL SHA256 CA
DN SHA-256
d9c0cf80d24b6ca967ddfaa559aca93678dbd20210da3eeff2852df8f2f63987
Issuer DER
MEIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMRswGQYDVQQDExJSYXBpZFNTTCBTSEEyNTYgQ0E=

Context

Bugzilla
1480853
Action
Two certificates were added to OneCRL by w**********r@mozilla.com on 2018-08-29 17:32:10Z and 2018-08-29 17:33:12Z; both entries were enabled and marked key compromise.
Confidence
Explicit in OneCRL thread · 0.96

CCADB Link

Issuer CA
RapidSSL SHA256 CA
CA Owner
DigiCert

AI Summary

Generated 2026-06-30 11:09 UTC · Model: gpt-5.4-mini

Wayne Thayer opened this CA Program bug on 2018-08-03 after reporting that the private key for a certificate used by localhost.megasyncloopback.mega.nz was embedded in client software. He initially asked that the referenced certificate be added to OneCRL, and later clarified that the relevant object was a precertificate and identified the corresponding certificate plus a second certificate sharing the same private key. On 2018-08-30 he stated that these certificates had been added to OneCRL. The OneCRL entries show two enabled revocations added by w**********r@mozilla.com on 2018-08-29, both with detail_why set to key compromise. The thread does not state a CCADB revocation field or candidate-report state as the trigger, so that qualification is unknown from the explicit record. The external cause is explicit: a compromised private key reported in Mozilla dev security policy, involving the MEGA-related localhost.megasyncloopback.mega.nz certificate and a second Comodo-signed certificate using the same key.

OneCRL action

Two certificates were added to OneCRL by w**********r@mozilla.com on 2018-08-29 17:32:10Z and 2018-08-29 17:33:12Z; both entries were enabled and marked key compromise.

CCADB trigger

Unknown / not stated; OneCRL entries only show detail_why=key compromise, with no explicit CCADB revocation field or candidate-report state cited.

External cause

Compromised private key for localhost.megasyncloopback.mega.nz reported in Mozilla dev security policy; a second certificate sharing the same private key was also identified. No CA closure is stated.

Confidence

Explicit in OneCRL thread · 0.96

Chronology
  • 2018-08-03Bug 1480853 opened reporting a compromised private key and requesting OneCRL addition.
  • 2018-08-06Wayne Thayer clarified the original reference was a precertificate and identified the corresponding certificate plus a second certificate sharing the same private key.
  • 2018-08-29Two OneCRL entries were created by w**********r@mozilla.com with detail_why set to key compromise.
  • 2018-08-30Wayne Thayer stated that the certificates had been added to OneCRL.

AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.

Raw Remote Settings Record

{
    "schema": 1552492994435,
    "details": {
        "bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1480853",
        "who": "wthayer@mozilla.com",
        "why": "key compromise",
        "name": "",
        "created": "2018-08-29T17:33:12Z"
    },
    "enabled": true,
    "issuerName": "MEIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMRswGQYDVQQDExJSYXBpZFNTTCBTSEEyNTYgQ0E=",
    "serialNumber": "L41amoCH4B2agSUpD8Wd2A==",
    "id": "8a401bee-cee4-40d8-a61e-903ca0cda17f",
    "last_modified": 1535564772595
}

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action