QuoVadis: delayed revocation of EV QWAC certificates (BR revocation requirement)
QuoVadis reported that it had issued Qualified Web Authentication Certificates (QWAC) with an EV OID containing Organisationidentifier fields, and that during audit procedures certain certificates were identified for revocation. The thread states that QuoVadis accepted responsibility for revocation taking longer than the five days allowed in the BR, and that the original policy settings were restored in production following the effective date of Ballot SC17 on June 21, 2019. The CA states that it revoked the first and second certificates on 6/7/2019 and later revoked the remaining certificates on 7/2/2019, with the final two certificates experiencing difficulties replacing the certificates and delayed revocation. QuoVadis explains that it allowed more time to avoid disproportionate business damage to the certificate holder and that an important relying party (a government regulator) had pinned the original certificates, preventing simple replacement. Mozilla staff emphasized that Mozilla does not grant exceptions to BR revocation requirements and requested clear timelines and remediation. DigiCert/QuoVadis responded that compliance controls were moved to DigiCert proper, training would be provided to the QuoVadis team, and incident reporting/remediation planning would be prepared; Compliance also communicated revocation requirements and conducted education with QuoVadis personnel by 7/30/2019. A later comment states that remediation is complete.
- Ballot SC17 effective date; QuoVadis restored original policy settings in production.
- QuoVadis provided a written timeline to address the identified certificate issues.
- QuoVadis revoked the final two certificates after delayed revocation.
- Planned deadline for Compliance notification and education on the revocation process across QuoVadis personnel.
- Compliance communicated revocation requirements and conducted education with QuoVadis personnel.
- A participant stated remediation was complete.
- DigiCert — Stephen Davidson described that QuoVadis issued EV QWAC certificates with Organisationidentifier fields, that prior templates were not fully removed, and provided a timeline including revocations and audit identification.
- Community commenter — Ryan Sleevi asked what steps were being taken to prevent future delayed revocation and referenced Mozilla’s incident response guidance.
- DigiCert — Brenda Bernal confirmed the case was part of the hierarchy DigiCert acquired and that Stephen would respond to other questions.
- DigiCert — Stephen Davidson stated QuoVadis accepted responsibility for revocation taking longer than five days, explained the rationale and the relying party pinning issue, and described integration into DigiCert compliance resources.
- Community commenter — Ryan corrected the record by stating Mozilla does not grant exceptions to BR revocation requirements and requested a follow-up response with compliance timelines.
- DigiCert — Jeremy Rowley said compliance control was moved to DigiCert proper, training would be provided to the QuoVadis team, and a follow-up incident report would be prepared.
- DigiCert — Brenda Bernal stated alignment and integration into DigiCert compliance processes had started and that revocation-process education would occur no later than 29-July-2019.
- DigiCert — Brenda provided an update that Compliance communicated revocation requirements and conducted education with QuoVadis personnel.
- Fastly representative — W. Thayer stated it appeared all questions were answered and remediation was complete.