DigiCert EV enablement request for Assured ID Root CA and Global Root CA was withdrawn after review and revocation follow-up
This case was a request to EV-enable the DigiCert Assured ID Root CA and DigiCert Global Root CA, both of which were already included with Websites and Email trust bits. DigiCert later asked to add Baltimore CyberTrust Root to the request, but Mozilla reviewers said that would raise broader concerns and should not be bundled into the EV request. During review, Mozilla raised questions about DigiCert’s CP/CPS, audit coverage, and several misissuance and revocation issues under related intermediates. DigiCert responded with clarifications, updated its CP and CPS, and said it would revoke the valid misissued certificates identified in the discussion. In July 2019 DigiCert said the remaining certificates requiring revocation had been revoked, and in August 2019 it said all required revocations had been actioned and asked to close the bug because it was no longer seeking EV enablement. The bug was then closed as the EV request was withdrawn.
- DigiCert requested EV treatment for DigiCert Global Root CA and DigiCert Assured ID Root CA.
- DigiCert asked to add Baltimore CyberTrust Root to the EV request.
- Mozilla began public discussion of the EV enablement request.
- DigiCert said the remaining certificates needing revocation were revoked.
- DigiCert said it was no longer requesting EV enablement and asked to close the bug.
- Community commenter — Ben Wilson opened the request to EV-enable DigiCert Global Root CA and DigiCert Assured ID Root CA and provided audit, hierarchy, and certificate details.
- Mozilla representative — Kathleen Wilson said the request information had been entered into Salesforce and asked DigiCert to review it for accuracy and completeness.
- DigiCert — Jeremy Rowley said the information was old, asked what needed updating, and noted that chain information was now in CCADB.
- Mozilla representative — Aaron asked DigiCert to complete a BR self-assessment and attach it to the bug.
- DigiCert — Steve Medin attached DigiCert’s BR self-assessment.
- Mozilla representative — Kathleen Wilson said the request still needed clarification on private-key generation and external sub-CAs or cross-certs.
- DigiCert — Jeremy Rowley said DigiCert never generates private keys for SSL certs, would clarify that in the CPS, and said the CPS did not prevent external sub-CAs though DigiCert had no plans for additional TLS issuance from these roots.
- Fastly representative — Wayne Thayer listed concerns about audit continuity, domain validation methods, subordinate CAs, misissued certificates, liability language, and email verification procedures.
- Community commenter — Ben Wilson replied to Wayne’s concerns, cited audit coverage, said DigiCert intended to remove deprecated validation methods, and said some identified certificates would be reviewed for revocation.
- Fastly representative — Wayne Thayer started public discussion on mozilla.dev.security.policy and summarized the request, audits, and remaining concerns.
- Fastly representative — Wayne Thayer followed up that the valid misissued certificates under DigiCert SHA2 Secure Server CA appeared revoked, but TERENA SSL CA 3 still needed an update.
- DigiCert — Jeremy Rowley said the TERENA SSL CA 3 certificates were all revoked and that DigiCert was checking the rest of the list.
- DigiCert — Brenda Bernal said all certificates requiring revocation had been actioned and DigiCert was no longer requesting EV enablement.
- Fastly representative — Wayne Thayer closed the EV request per DigiCert’s withdrawal.