DigiCert: TERENA: No localityName in EV precert
The bug was opened after an external reporter found two unrevoked EV precertificates issued by TERENA that appeared to lack a localityName in the subject. The reporter noted they could not find corresponding leaf certificates and linked to the precertificates via crt.sh. DigiCert’s assigned representative (Jeremy Rowley) stated that localityName is not a required field in this situation, citing EV Guidelines Section 9.2.6 and explaining that the certificate includes the state but not the locality, which is appropriate for the organization. The representative also clarified the certificate field requirements for localityName based on whether stateOrProvinceName and other subject fields are present. A third party agreed the crt.sh/cablint linting was showing a false positive and referenced upstream linting fixes. The original reporter later apologized for the misreport, saying they assumed an issue based on tool output and would be more careful in the future. The bug was resolved as INVALID.
- An external reporter identified two EV precertificates from TERENA that appeared to be missing localityName and opened a CA Program compliance bug.
- DigiCert responded that localityName was not required for the specific certificate subject fields and characterized the report as a false positive.
- A third party agreed the linting output was a false positive and pointed to upstream certlint/x509lint fixes.
- The reporter apologized for the misreport after re-checking the guidelines.
- DigiCert thanked the reporter for the input and flagging.
- Lebihan representative — Reported two unrevoked EV precertificates issued by TERENA that lacked localityName and linked to the crt.sh entries, noting they could not find corresponding leaf certificates.
- DigiCert — Said localityName is not required in this case per EV Guidelines Section 9.2.6 and that the report is a false positive.
- DigiCert — Provided detailed EV guideline-based requirements for when localityName is required/optional/prohibited and explained the certificate includes state but not locality.
- Sectigo — Agreed it is a false positive from crt.sh/cablint and referenced upstream linting fixes and related PRs.
- Lebihan representative — Apologized for the misreport, stating they assumed an issue from tool output and would be more careful.
- DigiCert — Acknowledged the reporter’s note and thanked them.