DigiCert: Non-BR Compliant Certificates - missing CP/CPS OID
The case reports that certificates issued by new CAs in a DigiCert-related SSL issuance environment were missing the CP/CPS OID during preproduction testing. The issue was identified as non-aligned with the Baseline Requirements, even though the CA stated it did not represent a security issue and only a handful of impacted certificates were public-facing. DigiCert located the error causing the mislabeling and corrected it, and stated that certificates were otherwise issued in accordance with Baseline Requirements. DigiCert also reported revocation progress: 80% of the certificates were revoked initially, with the intent to revoke 100% by the next update. The thread later states that all of these certs were revoked, and that the system was patched to ensure a CP OID is included each time. The bug is marked RESOLVED with resolution FIXED.
- During preproduction testing of a new SSL issuance environment, DigiCert identified that certificates issued by new CAs were missing the CP/CPS OID.
- DigiCert corrected the error causing the CP/CPS OID mislabeling and began revoking impacted certificates.
- DigiCert reported that all impacted certificates were revoked.
- DigiCert stated the system was patched to include the CP OID each time and indicated the issue could be closed.
- DigiCert — Jeremy Rowley explained that certificates issued in a new environment were missing the CP/CPS OID, identified the error, corrected it, and stated Microsoft took action to prevent recurrence.
- Mozilla representative — Kathleen Wilson asked to be kept updated on remaining action items and when the concern was fully resolved.
- DigiCert — Jeremy Rowley reported that 80% of the certificates had been revoked and that 100% would be revoked by the next update.
- DigiCert — Jeremy Rowley updated that all of these certs are revoked.
- DigiCert — Jeremy Rowley suggested the bug could be closed, stating all certs were revoked and the system was patched to include the CP OID each time.