← DarkMatter LLC cases
Bugzilla #1563917
Certificate Problem Report
QuoVadis: use of Organisationidentifier field in EV (Pre CABF Ballot SC17)
RESOLVED
FIXED
DarkMatter LLC
AI Summary
QuoVadis issued several Qualified Web Authentication Certificates (QWAC) that incorrectly included the Organisationidentifier field, which was not compliant with the CA/Browser Forum's guidelines. The issue was identified during an audit, leading to the revocation of four certificates. The revocation process faced delays due to potential business impacts on clients, particularly because of certificate pinning by a regulatory entity. QuoVadis has since restored compliance and is implementing additional controls to prevent future occurrences.
Chronology
- Issue identified verbally
- First certificate revoked
- Second certificate revoked
- Third and fourth certificates revoked
- Compliance education on revocation process initiated
- Compliance communicated revocation requirements
- Remediation confirmed complete
Participants
Stephen Davidson
Ryan Sleevi
Brenda Bernal
Jeremy Rowley
External References
Similar Local Cases
QuoVadis: Failure to revoke certificates with compromised private keys
QuoVadis: EV serialNumber with "none"
QuoVadis: Incorrect EV jurisdiction of incorporation information
QuoVadis: Failure to provide a preliminary report within 24 hours.
QuoVadis: failure to reply to CPR in a timely manner
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs
QuoVadis: Incorrect keyUsage for ECC certificate
QuoVadis: N/A in EV serialNumber field