In a controlled 2017 test, security researcher Hanno Böck reported that Symantec revoked his test certificate after he submitted a fabricated RSA private key that copied the certificate’s public-key values but contained invalid private components. Comodo, which received a similar report, identified a bad key. Böck said the only observed impact was revocation of his own test certificate; the incident did not demonstrate that an unrelated customer’s certificate was revoked.
How the fake-key test worked
In a post published July 20, 2017, Böck described obtaining short-term test certificates for two domains through Symantec’s RapidSSL service and Comodo. He constructed fake RSA private keys that reused public values from a certificate but did not contain valid corresponding private-key material. To make the report less conspicuous, he combined the forged keys with reports about genuinely exposed keys he had found online.
In that 2017 search, Böck said he found seven exposed Comodo private keys and three exposed Symantec private keys, as well as keys associated with other certificate authorities. Those are his findings from that search, not estimates of overall exposure or current conditions. Böck’s account describes the test and the mixed submission.
How the two certificate authorities responded
| Certificate authority | What Böck reported | What the test establishes |
|---|---|---|
| Comodo | Böck said Comodo noticed that a submitted key was wrong. | It identified a bad key in this test; this single case does not establish how Comodo performs across other cases. |
| Symantec | Böck said Symantec told him it had revoked all certificates in the report, including his test certificate associated with a forged key. | The test certificate was revoked. Böck reported no harm beyond that certificate, which covered his own test domain. |
Symantec’s reported response acknowledged a gap in its third-party revocation process. SecurityWeek quoted the company: “First, a gap was identified in the public and private key matching process where keys are verified during the revocation request procedure.” The company said it had compared RSA moduli but had not checked other key parameters, and that it corrected the process after learning of the problem. It also said it knew of no customer impact beyond Böck’s test and would review how it communicated with certificate owners during third-party revocations. SecurityWeek’s July 21, 2017 report reproduces the company’s explanation.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
Why copying the public values was not enough
A certificate contains public-key information. A private key presented as evidence of compromise must be both valid private-key material and mathematically associated with that certificate’s public key. Copying public values into a fabricated private-key structure does not make its private components valid.
Symantec’s reported check compared RSA moduli, an important part of matching keys, but the company said it failed to verify other parameters. Böck described checking the derived public key and using a sign-and-verify test to establish that a private key works with the certificate’s public key. Those are distinct from merely finding matching public values. Böck’s technical account explains the comparison and verification issue.
Why a certificate authority accepts reports—and what must be checked
Certificate authorities need a way to respond quickly when a private key is genuinely compromised. Böck cited section 4.9.1.1 of the CA/Browser Forum Baseline Requirements version 1.4.8, which called for revocation within 24 hours when a CA had evidence of key compromise. A Symantec-associated CrossCert Certification Practice Statement likewise specified revocation within 24 hours after the CA obtained evidence that a subscriber private key had been compromised.
That historical deadline explains the need for a prompt reporting path; it does not make an unvalidated submission proof of compromise. The CrossCert policy described both authenticated subscriber requests and a channel for any person to submit a certificate problem report, with investigation and action within the prescribed time. The policy is historical and does not establish current procedures for any successor service. The CA/Browser Forum Baseline Requirements, version 1.4.8 and the CrossCert Certification Practice Statement provide that period’s policy context.
Rank #3
- Validate that submitted private-key material is structurally and mathematically valid.
- Verify that the key actually corresponds to the certificate, rather than relying on a single public parameter.
- Preserve the ability to investigate quickly enough to meet applicable revocation deadlines.
- Communicate clearly with certificate owners when a third party reports a problem.
What the incident does—and does not—show
The demonstrated result was a controlled test affecting Böck’s own domain: Symantec revoked his test certificate after accepting the forged-key report, while Comodo identified a bad key in a similar submission. Böck said no harm occurred beyond his test certificate.
The potential risk is that a flawed verification process could let someone trigger an unwanted revocation by submitting fabricated evidence, possibly disrupting a site that depends on the certificate. The test did not show that an unrelated customer’s certificate was revoked or that such disruption took place. Böck also criticized the notice and explanation he received as the certificate owner; the evidence here concerns this 2017 episode and does not establish current revocation procedures.
Quick Recap
Best Value
Rank #4
- 2-part carbonless unit set
- Consecutive numbering
- Includes Gift Certificates Available sign
- 25 certificates with envelopes per package
- White/canary form sequence
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

