QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy/BRs
Ryan Sleevi opened this bug after a spot-check of Mozilla Policy Compliance found that QuoVadis issued an intermediate certificate (“QuoVadis EU Issuing Certification Authority G4”) on 2019-05-14 that did not conform to Mozilla Policy 2.6.1. The reported issues were that the intermediate lacked an extendedKeyUsage extension and asserted an organizationIdentifier in the Subject, which Ryan stated would conflict with Baseline Requirements sections 7.1.2.4 and 7.1.4.3.1. Stephen Davidson responded with an incident report describing how the issue was identified during investigation of bug 1581597, confirming that no TLS certificates had been issued from the CA, and providing context about the CA renewal and QuoVadis’s checklist/process changes. QuoVadis accepted the issuance as a mistake and stated that its renew checklists were changed, with follow-up planned to replace the CA with an EKU-constrained version. Jeremy Rowley and Stephen Davidson discussed the interpretation of the requirements and noted process integration steps after the renewal. The CA certificate was revoked/superseded effective October 15, 2019, and a later comment stated that remediation appeared complete. The bug is marked RESOLVED with resolution FIXED.
- QuoVadis issued the intermediate “QuoVadis EU Issuing Certification Authority G4” that lacked an extendedKeyUsage extension.
- Mozilla policy compliance spot-check identified the non-conforming intermediate and opened the incident bug.
- The CA certificate was revoked/superseded via CRL effective October 15, 2019.
- A participant indicated remediation was complete.
- Community commenter — Reported that the QuoVadis intermediate issued on 2019-05-14 lacked extendedKeyUsage and included an organizationIdentifier, and requested an Incident Report.
- DigiCert — Provided an incident report describing discovery during investigation of bug 1581597, stated no TLS certificates were issued, and outlined corrective actions including changing renew checklists and replacing the CA with an EKU-constrained version.
- Community commenter — Questioned QuoVadis’s explanation about misunderstanding applicability to renewals and asked how future confusion would be prevented.
- DigiCert — Responded that the QuoVadis PKI team integrated into DigiCert PKI Operations and adopted practices like checklists and review signoffs, and discussed interpretation of BR section 7.1.4.3.1.
- Community commenter — Asked for links supporting the asserted confusion and criticized the response as not providing long-term assurances or solutions for future incidents.
- DigiCert — Agreed revocation was needed, described integration steps and controls, and said he would coordinate to revoke the ICA right away.
- DigiCert — Announced the CA certificate was revoked/superseded effective October 15, 2019 and provided a crt.sh link.
- Fastly representative — Stated it appeared all questions were answered and remediation was complete.