← DigiCert cases
Bugzilla #1581234 Ca Certificate Compliance Self Reported Incident

QuoVadis: EV JOI Issue

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

QuoVadis identified a compliance issue related to the use of abbreviations in the jurisdictionStateOrProvinceName field of their EV certificates. The issue was discovered during a proactive review initiated in response to a related incident involving DigiCert. QuoVadis took immediate action by revoking 413 affected certificates and clarifying their validation procedures. The CA has committed to using only ISO 3166-2 and government-provided references for geographic names moving forward. The remediation process included a manual review of templates and a focus on compliance improvements. The case has been resolved with all questions answered and remediation deemed complete.

Model: gpt-4o-mini Generated: 2026-06-13 19:35 UTC Revised: 2026-06-16 18:45 UTC Confidence: 0.85 11 comments
Chronology
  1. Batch 1 of affected certificates revoked.
  2. Investigation completed on use of abbreviations in EV JOI.
Thread Activity
  1. DigiCert — Created an attachment detailing the timeline and actions taken regarding the EV JOI issue.
  2. DigiCert — Certificates revoked and customers informed.
  3. Fastly representative — All questions have been answered and remediation is complete.
  4. Community commenter — Expressed concerns about the lack of detail in the response.
  5. Community commenter — Expressed disappointment regarding the clarity of QuoVadis' operations.
  6. Fastly representative — Confirmed that all questions have been answered and remediation is complete.
Participants
DigiCert Fastly representative Community commenter
Similar Local Cases
#1579950 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-09 · Closed 2022-11-14 · 100% similar
QuoVadis: OCSP handling of Certificate Transparency Pre-certs
#1624504 RESOLVED Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 95% similar
QuoVadis: Failure to revoke certificates with compromised private keys
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 88% similar
DigiCert: Issuance of Cert with Compromised Key
#1649938 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 87% similar
QuoVadis: Incorrect OCSP Delegated Responder Certificate
#1738472 RESOLVED Self Reported Incident Opened 2021-10-29 · Closed 2023-02-22 · 86% similar
QuoVadis: hostnames not in preferred name syntax
#1618256 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-02-26 · Closed 2023-02-22 · 86% similar
DigiCert: Failure to properly encode Subject name
#1575022 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2019-08-19 · Closed 2023-02-22 · 86% similar
Sectigo: EV SSL Certificates with incorrect subject details.
#1586860 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-10-07 · Closed 2023-02-22 · 86% similar
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action