DigiCert disclosure and audit-scoping failures for intermediates and legacy Apple IST CAs
This case concerns DigiCert’s disclosure and audit-record handling for intermediate certificates in CCADB, including a set of Apple IST CAs and other intermediates that were reported as missing or incorrectly marked. The bug was opened by Ryan Sleevi after he identified that DigiCert had failed to properly disclose intermediates within the required time period, and DigiCert responded that the issue involved confusion about how to mark new ICAs and a gap in its internal review process. DigiCert said it would review and correct CCADB records, add compliance oversight, and implement two-person controls, checklists, and later automation to compare its internal database against CCADB. For the Apple IST CAs, DigiCert and Mozilla discussed remediation, and Mozilla stated that adding the affected certs to OneCRL and providing an incident report were sufficient for those certs. The bug was later updated with additional disclosures, audit clarifications, revocations for some certificates, and ongoing process changes, and the bug status is RESOLVED with FIXED resolution.
- Ryan Sleevi reported DigiCert intermediates that were not properly disclosed in CCADB within the required time period.
- DigiCert said the reported CAs were disclosed but that audit and CPS information was incomplete.
- DigiCert proposed a CCADB handling policy for DigiCert-operated, third-party-operated, and technically constrained issuing CAs.
- DigiCert provided a timeline explaining the Adacom/KIBS intermediate audit and disclosure issue.
- DigiCert said Apple would complete prior-period audits by 2019-09-30 and added a policy requirement for third-party scope review before audit finalization.
- Mozilla said adding the Apple IST 5, 6, and 7 certs to OneCRL and providing an incident report would be sufficient for that scenario.
- DigiCert reported that Apple IST CA 6 and 7 were revoked, with Apple IST CA 5 to be revoked next.
- DigiCert disclosed three ICAs created on 2019-10-16 that were not loaded into CCADB until 2019-10-31.
- DigiCert said it had tested its script but had not yet tested it in a live key ceremony before closing the bug.
- Community commenter — Ryan Sleevi opened the bug and asked DigiCert for an incident report and a binding commitment after identifying multiple intermediates that were not properly disclosed in CCADB.
- DigiCert — Brenda Bernal replied that DigiCert believed the CAs were disclosed but that audit and CPS information was incomplete, and said an incident report would follow.
- Community commenter — Ryan Sleevi raised broader concerns about DigiCert’s CCADB disclosures and asked for consistent handling of intermediate audit information.
- DigiCert — Jeremy Rowley said DigiCert wanted Mozilla policy clarification on how to mark new ICAs in CCADB and said DigiCert would file an incident report.
- DigiCert — Brenda Bernal posted DigiCert’s incident report, including a timeline, affected certificates, and a statement that DigiCert was refining its CCADB update process.
- DigiCert — Jeremy Rowley said DigiCert was restructuring CCADB handling so PKI Ops would provide initial data and Compliance would review each upload.
- DigiCert — Jeremy Rowley reported that DigiCert had reviewed 1,099 items and found two incorrectly marked intermediates controlled by Adacom, which were to be revoked shortly.
- DigiCert — Jeremy Rowley corrected earlier confusion and gave a detailed history of the KIBS/Adacom intermediates, concluding that the issue was human error and that the affected CAs were revoked.
- DigiCert — Brenda Bernal said Apple was working with auditors to amend reports and referenced a separate incident report for Apple.
- DigiCert — Brenda Bernal said DigiCert would keep monitoring Apple’s remediation and described broader compliance process improvements.
- DigiCert — Brenda Bernal said Apple’s prior-period audits were expected by 2019-09-30, that DigiCert had added a third-party scope-review policy requirement, and that unaudited CAs would be covered by audit or discontinued use and likely revocation.
- DigiCert — Jeremy Rowley agreed to use OneCRL as the remediation approach for the Apple IST certs and said it should not be treated as a general remediation mechanism.
- Mozilla representative — Kathleen Wilson said Mozilla considered adding the Apple IST 5, 6, and 7 certs to OneCRL and providing an incident report to be sufficient for that case.
- DigiCert — Brenda Bernal reported that Apple IST CA 6 and 7 had been revoked and that Apple IST CA 5 would be revoked the following week.
- DigiCert — Jeremy Rowley said DigiCert was building a notification system to compare its internal database with CCADB and alert PKI Ops and Compliance about missing entries.
- DigiCert — Jeremy Rowley said the bug was still in triage, that the script had been tested, and that DigiCert wanted a live key ceremony test before closing the bug.