← DigiCert cases
Bugzilla #1165472 Ev Enablement

DigiCert EV enablement request for Assured ID Root CA and Global Root CA was withdrawn after review and revocation follow-up

RESOLVED WONTFIX DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case was a request to EV-enable the DigiCert Assured ID Root CA and DigiCert Global Root CA, both of which were already included with Websites and Email trust bits. DigiCert later asked to add Baltimore CyberTrust Root to the request, but Mozilla reviewers said that would raise broader concerns and should not be bundled into the EV request. During review, Mozilla raised questions about DigiCert’s CP/CPS, audit coverage, and several misissuance and revocation issues under related intermediates. DigiCert responded with clarifications, updated its CP and CPS, and said it would revoke the valid misissued certificates identified in the discussion. In July 2019 DigiCert said the remaining certificates requiring revocation had been revoked, and in August 2019 it said all required revocations had been actioned and asked to close the bug because it was no longer seeking EV enablement. The bug was then closed as the EV request was withdrawn.

Model: gpt-5.4-mini Generated: 2026-06-13 11:02 UTC Revised: 2026-06-16 18:33 UTC Confidence: 0.96 45 comments
Chronology
  1. DigiCert requested EV treatment for DigiCert Global Root CA and DigiCert Assured ID Root CA.
  2. DigiCert asked to add Baltimore CyberTrust Root to the EV request.
  3. Mozilla began public discussion of the EV enablement request.
  4. DigiCert said the remaining certificates needing revocation were revoked.
  5. DigiCert said it was no longer requesting EV enablement and asked to close the bug.
Thread Activity
  1. Community commenter — Ben Wilson opened the request to EV-enable DigiCert Global Root CA and DigiCert Assured ID Root CA and provided audit, hierarchy, and certificate details.
  2. Mozilla representative — Kathleen Wilson said the request information had been entered into Salesforce and asked DigiCert to review it for accuracy and completeness.
  3. DigiCert — Jeremy Rowley said the information was old, asked what needed updating, and noted that chain information was now in CCADB.
  4. Mozilla representative — Aaron asked DigiCert to complete a BR self-assessment and attach it to the bug.
  5. DigiCert — Steve Medin attached DigiCert’s BR self-assessment.
  6. Mozilla representative — Kathleen Wilson said the request still needed clarification on private-key generation and external sub-CAs or cross-certs.
  7. DigiCert — Jeremy Rowley said DigiCert never generates private keys for SSL certs, would clarify that in the CPS, and said the CPS did not prevent external sub-CAs though DigiCert had no plans for additional TLS issuance from these roots.
  8. Fastly representative — Wayne Thayer listed concerns about audit continuity, domain validation methods, subordinate CAs, misissued certificates, liability language, and email verification procedures.
  9. Community commenter — Ben Wilson replied to Wayne’s concerns, cited audit coverage, said DigiCert intended to remove deprecated validation methods, and said some identified certificates would be reviewed for revocation.
  10. Fastly representative — Wayne Thayer started public discussion on mozilla.dev.security.policy and summarized the request, audits, and remaining concerns.
  11. Fastly representative — Wayne Thayer followed up that the valid misissued certificates under DigiCert SHA2 Secure Server CA appeared revoked, but TERENA SSL CA 3 still needed an update.
  12. DigiCert — Jeremy Rowley said the TERENA SSL CA 3 certificates were all revoked and that DigiCert was checking the rest of the list.
  13. DigiCert — Brenda Bernal said all certificates requiring revocation had been actioned and DigiCert was no longer requesting EV enablement.
  14. Fastly representative — Wayne Thayer closed the EV request per DigiCert’s withdrawal.
Participants
Community commenter Mozilla representative DigiCert Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1339292 RESOLVED Ev Enablement Opened 2017-02-14 · Closed 2022-11-14 · 86% similar
Enable EV for "IdenTrust Commercial Root CA 1"
#403644 RESOLVED Ev Enablement Opened 2007-11-13 · Closed 2022-11-14 · 78% similar
Request for CA Root Certificate be enabled for EV (DigiCert High Assurance EV Root CA)
#515425 RESOLVED Trust Bit Enablement Opened 2009-09-09 · Closed 2022-11-14 · 70% similar
Request to enable code-object-signing "trust bit" for DigiCert's three Root CAs
#794036 RESOLVED Ev Enablement Opened 2012-09-25 · Closed 2022-11-14 · 69% similar
Enable EV for Firmaprofesional
#1277336 RESOLVED Root Inclusion Trust Bit Enablement Ev Enablement Opened 2016-06-01 · Closed 2022-11-14 · 66% similar
Add SSL.com root certificate(s)
#1390803 RESOLVED Root Inclusion Ev Enablement Incident Opened 2017-08-16 · Closed 2022-11-14 · 65% similar
Add "GlobalSign Root CA - R6" root certificate
#1585951 RESOLVED Root Inclusion Ev Enablement Opened 2019-10-03 · Closed 2023-05-02 · 57% similar
Add ANF AC root certificates
#1563573 RESOLVED Incident Opened 2019-07-04 · Closed 2023-02-22 · 51% similar
DigiCert: Failure to disclose Unconstrained Intermediate within 7 Days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action