Doesn't the CA forum baseline require a revocation if the private key is published?
https://cabforum.org/wp-content/uploads/CAB-Forum-BR-1.3.0.p... on page 18:
The CA SHALL revoke a Certificate within 24 hours
if one or more of the following occurs:
(...)
3. The CA obtains evidence that the Subscriber’s
Private Key corresponding to the Public Key in the
Certificate suffered a Key Compromise or no longer
complies with the requirements of Appendix A;Comodo website is not that good apparently.
Edit: in the document posted by brohee: (about authentication for certs revocation) "OR the Subscriber must be able to send an S/MIME email signed with the private key associated with the Certificate". That's doable :)
4.9.2 Who can Request Revocation A Subscriber or another appropriately authorized party can request revocation of a Certificate. An authorized party includes an RA, regardless of whether on behalf of the Subscriber may request revocation through their account. Other parties may report suspected Private Key Compromise, Certificate misuse, or other types of fraud, compromise, misuse, inappropriate conduct, or any other matter related to Certificates, in the first instance, by email to sslabuse@comodo.com.
https://www.comodo.com/repository/Comodo_CA_CPS_4.1.4.pdf
4.9.1 Circumstances for Revocation Comodo may revoke a digital Certificate if any of the following occur:
A personal identification number, Private Key or password has, or is likely to become known to someone not authorized to use it, or is being or is likely to be used in an unauthorized way