DigiCert: Symantec non-constrained/non-disclosed intermediate CA certificates
This case involves DigiCert's proactive disclosure of compliance issues related to non-constrained and non-disclosed intermediate CA certificates that were part of the former Symantec infrastructure. The CA identified that there were 279 intermediate CAs that had not been reported in the Common CA Database (CCADB). DigiCert is working to upload these CAs to CCADB and ensure they are properly audited. The resolution involves including these CAs in the upcoming audit report and addressing compliance issues by migrating them to a hosted solution or ensuring they are audited and properly verifying email addresses. The case has been marked as resolved.
- DigiCert files a compliance report regarding non-constrained intermediate CAs.
- DigiCert provides a list of intermediate CAs to be included in the audit.
- DigiCert confirms that compliance issues are being addressed through audits and CCADB updates.
- DigiCert — Filed a compliance report regarding 279 non-constrained TLS-capable issuing CAs.
- DigiCert — Confirmed that all three groups of intermediate CAs will be included in the upcoming audit report.
- Community commenter — Explained the ongoing efforts to ensure all CAs are disclosed and audited as per Mozilla policy.