← DigiCert cases
Bugzilla #1581597 Ca Documents Audit Finding

QuoVadis unconstrained CAs missing BR audit disclosure and subsequent revocations

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns QuoVadis’ disclosure and audit coverage for 18 intermediate CAs that were technically capable of TLS issuance but were not actually used to issue TLS certificates. The issue was triggered when QuoVadis received an email from the Chrome Root Authority program on 2019-09-10 asking for confirmation of Baseline Requirements audit disclosures. QuoVadis investigated, met with auditors, and later had EY reissue the 2018 WebTrust for Baseline Requirements report to name the 18 CAs; it also reissued the 2018 WebTrust for EV report to add one omitted EV ICA. QuoVadis then revoked the affected CAs in stages, requested OneCRL inclusion, and retained EY for an attestation report covering 2014–2017 for the remaining unrevoked CAs. The final two actions were delayed by COVID-19 restrictions, but QuoVadis later completed revocation of QuoVadis Swiss Advanced CA G2 and key destruction for QuoVadis Issuing CA G4. The bug was resolved after the audit report and key-destruction confirmation were provided.

Model: gpt-5.4-mini Generated: 2026-06-13 20:00 UTC Revised: 2026-06-16 18:45 UTC Confidence: 0.95 42 comments
Chronology
  1. QuoVadis learned of missing Baseline Requirements audit disclosure for 18 intermediate CAs.
  2. EY reissued the 2018 WebTrust for Baseline Requirements and EV reports to correct the disclosures.
  3. QuoVadis Personal Signing Service CA G1 was revoked.
  4. Several additional QuoVadis issuing CAs were revoked, leaving two remaining CAs.
  5. QuoVadis Swiss Advanced CA G2 was revoked and QuoVadis Issuing CA G4 underwent key destruction.
  6. EY completed validation of the key destruction procedures for QuoVadis Issuing CA G4.
Thread Activity
  1. DigiCert — Stephen Davidson opened the case and explained that QuoVadis found 18 ICAs that were not disclosed in the BR report because they did not issue TLS certificates.
  2. Mozilla representative — Kathleen Wilson asked Stephen to verify the spreadsheet of items to be added to OneCRL and noted the CCADB records were marked Ready to Add.
  3. Community commenter — QuoVadis said it had reconciled all ICAs to the 2018 WebTrust reports and that EY would reissue the BR and EV reports.
  4. Community commenter — QuoVadis reported that EY had reissued the 2018 BR report to name the 18 CAs and reissued the EV report to add the omitted EV ICA.
  5. DigiCert — Stephen Davidson said six of the CAs had been revoked, OneCRL had been requested, and EY had been retained for an AT-C 105 attestation report for 2014–2017.
  6. DigiCert — QuoVadis said it was still replacing end-entity certificates under the remaining two subCAs and described a plan for QuoVadis Issuing CA G4 involving TSA certificates, pre-generated CRLs, and key destruction.
  7. DigiCert — QuoVadis said EY’s attestation report confirmed the listed ICAs were in scope for BR procedures and had not issued TLS-capable certificates from 2014 through 2017.
  8. DigiCert — QuoVadis reported revocation of QuoVadis Swiss Advanced CA G2 and completion of a key destruction ceremony for QuoVadis Issuing CA G4.
  9. DigiCert — QuoVadis said EY had validated the key destruction procedures for QuoVadis Issuing CA G4 and provided the report to Mozilla representatives.
  10. Mozilla representative — Mozilla noted that the E&Y audit statement described physical observation of the CA destruction process.
Participants
DigiCert Mozilla representative Community commenter Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1588213 RESOLVED Ca Documents Audit Finding Opened 2019-10-11 · Closed 2024-06-30 · 95% similar
IdenTrust: Missing Thumbprints for Intermediate CA certificates In Some Annual Audit Reports
#1549862 RESOLVED Ca Documents Audit Finding Opened 2019-05-07 · Closed 2023-02-22 · 93% similar
Entrust: Outdated audit statement for intermediate cert
#1458024 RESOLVED Ca Documents Audit Document Self Assessment Auditor Qualification Opened 2018-04-30 · Closed 2026-07-13 · 91% similar
DigiCert WebTrust Audits
#1412950 RESOLVED Ca Documents Audit Finding Opened 2017-10-30 · Closed 2024-06-30 · 85% similar
Firmaprofesional: Insufficient Audit Statements
#1648593 RESOLVED Ca Documents Opened 2020-06-25 · Closed 2024-06-30 · 84% similar
Sectigo: Potential audit report delay
#1565270 RESOLVED Ca Documents Opened 2019-07-11 · Closed 2023-02-22 · 83% similar
Telia: Qualified BR Audit Statement
#1313445 RESOLVED Ca Documents Audit Finding Opened 2016-10-27 · Closed 2022-12-08 · 83% similar
Audit info for SECOM
#1650199 RESOLVED Ca Documents Audit Finding Opened 2020-07-02 · Closed 2022-12-08 · 83% similar
Network Solutions: Audit Reports

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action