Closed
Bug 1427034
Opened 7 years ago
Closed 7 years ago
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
Categories
(CA Program :: CA Certificate Compliance, task)
CA Program
CA Certificate Compliance
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: hanno, Assigned: kathleen.a.wilson)
References
Details
(Whiteboard: [ca-onecrl])
In bug #1425166 I had reported that Blizzard's battle.net application has a certificate and private key embedded for the domain localbattle.net that points to localhost, making it a key compromise.
For a few days Blizzard used a locally created CA and signed a cert from that (which is probably safe if done correctly). However it seems now they decided to go back to issuing a cert with an embedded private key, this time however from Digicert. (CCing Jeremy Rowley from Digicert, please consider this a report of a key compromise.)
This has already been reported to the public mailing list, so I'm not marking this bug private:
https://groups.google.com/d/msg/mozilla.dev.security.policy/pk039T_wPrI/VYi629oGCwAJ
| Reporter | ||
Comment 1•7 years ago
|
||
I submitted the cert to CT:
https://crt.sh/?id=287530764
Comment 2•7 years ago
|
||
Should we add this certificate to OneCRL? Doing so would be consistent with our handling of bug #1425166, but it's not clear to me if this certificate represents much of a threat to Firefox users.
Comment 3•7 years ago
|
||
This was revoked, but posting to Mozilla isn't the best way to report key compromise (because I don't man bugzilla 24z7). We revoke all certs within 24 hours of confirming key compromise if it's reported to revoke@digicert.com
Comment 4•7 years ago
|
||
J.C. and Mark, let's go ahead and add this certificate to OneCRL: https://crt.sh/?id=287530764
Flags: needinfo?(mgoodwin)
Updated•7 years ago
|
Flags: needinfo?(mgoodwin)
| Assignee | ||
Updated•7 years ago
|
Whiteboard: [ca-onecrl]
| Assignee | ||
Comment 5•7 years ago
|
||
Added to OneCRL.
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → FIXED
Updated•2 years ago
|
Product: NSS → CA Program
Updated•1 year ago
|
Summary: localbattle.net certificate with private key in software / issued by Digicert → DigiCert: localbattle.net certificate with private key in software / issued by Digicert
You need to log in
before you can comment on or make changes to this bug.
Description
•