OneCRL Entry
cb712a6d-3b3d-4642-b0f0-5f765f615559
Revocation Entry
- Status
- enabled
- Serial
5446AFD1447E977F13A4A4D18BBB12D6- Last Modified
- 2018-01-30 17:50:51 UTC
- Schema
- 1552493004389
Issuer
- DN
- C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Domain Validation CA SHA2
- DN SHA-256
465b62a2a3275c6252891d63086ef3b8fe5fc6c0c64fe8a6808250b3f9dc19e5- Issuer DER
MIGFMQswCQYDVQQGEwJQTDEiMCAGA1UEChMZVW5pemV0byBUZWNobm9sb2dpZXMgUy5BLjEnMCUGA1UECxMeQ2VydHVtIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MSkwJwYDVQQDEyBDZXJ0dW0gRG9tYWluIFZhbGlkYXRpb24gQ0EgU0hBMg==
Context
- Bugzilla
- 1433118
- Action
- A OneCRL entry was added for the end-entity certificate issued by Certum Domain Validation CA SHA2 with serial 5446AFD1447E977F13A4A4D18BBB12D6. The local OneCRL record shows it was created on 2018-01-30T17:48:22Z by j**********c@mozilla.com and marked with the reason "key compromise"; Kathleen Wilson later confirmed in the bug that the entry had been added.
- Confidence
- Explicit in OneCRL thread · 0.98
CCADB Link
- Issuer CA
- Certum Domain Validation CA SHA2
- CA Owner
- Asseco Data Systems S.A.
AI Summary
Generated 2026-06-30 11:48 UTC · Model: gpt-5.4Bug 1433118 documents a report that the private key for the certificate used by windows10.microdone.cn was embedded in software and therefore compromised. Hanno Boeck filed the bug on 2018-01-25 and provided proof of possession of the private key. Certum representative Arkadiusz Ławniczak stated on 2018-01-25 that the certificate with serial 54:46:af:d1:44:7e:97:7f:13:a4:a4:d1:8b:bb:12:d6 had just been revoked. Wayne Thayer then asked J.C. to add the certificate to OneCRL. The local OneCRL entry shows J.C. added the revoked certificate on 2018-01-30 with reason noted as key compromise. The thread states the initial external report had been sent to ia@certum.pl, but that address routed to a helpline ticket queue instead of the security and vetting team. Certum said the website contact address was incorrect and that they were working to change it to re@certum.pl. J.C. later said the matter was handled in Bug 1434354, and Kathleen Wilson confirmed the OneCRL entry had been added.
A OneCRL entry was added for the end-entity certificate issued by Certum Domain Validation CA SHA2 with serial 5446AFD1447E977F13A4A4D18BBB12D6. The local OneCRL record shows it was created on 2018-01-30T17:48:22Z by j**********c@mozilla.com and marked with the reason "key compromise"; Kathleen Wilson later confirmed in the bug that the entry had been added.
Explicitly stated revocation for key compromise, followed by a manual request in the bug from Wayne Thayer to J.C. to add the certificate to OneCRL. No CCADB candidate-report state is stated in the thread.
Explicitly stated compliance incident: the certificate's private key was embedded in distributed software, and the reporter demonstrated possession of the key. The thread also states the CA's published contact address was incorrect, causing the original report to go to a helpline queue instead of the security and vetting team.
Explicit in OneCRL thread · 0.98
- 2018-01-23Hanno Boeck emailed Certum's published contact address to report that the certificate and private key were embedded in software.
- 2018-01-25Bug 1433118 was filed reporting compromise of the private key for the windows10.microdone.cn certificate.
- 2018-01-25Wayne Thayer asked Certum whether it would revoke the certificate and why the initial report received no response.
- 2018-01-25Certum stated that certificate serial 54:46:af:d1:44:7e:97:7f:13:a4:a4:d1:8b:bb:12:d6 had just been revoked.
- 2018-01-25Wayne Thayer asked J.C. to add the certificate to OneCRL.
- 2018-01-26Certum confirmed the original report had been received on 2018-01-23 and began investigating why it was not noticed.
- 2018-01-30Certum said the published address i**********a@certum.pl was incorrect and routed the report to a helpline queue instead of the security and vetting team.
- 2018-01-30The local OneCRL entry was created by j**********c@mozilla.com for the revoked certificate with reason "key compromise".
- 2018-01-30J.C. commented that the OneCRL handling was done in Bug 1434354.
- 2018-01-31Kathleen Wilson confirmed that the entry had been added to OneCRL.
AI-generated from the OneCRL record and linked Bugzilla thread. Mozilla and CCADB records remain authoritative.
Raw Remote Settings Record
{
"schema": 1552493004389,
"details": {
"bug": "https://bugzilla.mozilla.org/show_bug.cgi?id=1433118",
"who": "jc@mozilla.com",
"why": "key compromise",
"name": "",
"created": "2018-01-30T17:48:22Z"
},
"enabled": true,
"issuerName": "MIGFMQswCQYDVQQGEwJQTDEiMCAGA1UEChMZVW5pemV0byBUZWNobm9sb2dpZXMgUy5BLjEnMCUGA1UECxMeQ2VydHVtIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MSkwJwYDVQQDEyBDZXJ0dW0gRG9tYWluIFZhbGlkYXRpb24gQ0EgU0hBMg==",
"serialNumber": "VEav0UR+l38TpKTRi7sS1g==",
"id": "cb712a6d-3b3d-4642-b0f0-5f765f615559",
"last_modified": 1517334651604
}