← DigiCert cases
Bugzilla #1586792 Ca Certificate Compliance Certificate Misissuance

QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy/BRs

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Ryan Sleevi opened this bug after a spot-check of Mozilla Policy Compliance found that QuoVadis issued an intermediate certificate (“QuoVadis EU Issuing Certification Authority G4”) on 2019-05-14 that did not conform to Mozilla Policy 2.6.1. The reported issues were that the intermediate lacked an extendedKeyUsage extension and asserted an organizationIdentifier in the Subject, which Ryan stated would conflict with Baseline Requirements sections 7.1.2.4 and 7.1.4.3.1. Stephen Davidson responded with an incident report describing how the issue was identified during investigation of bug 1581597, confirming that no TLS certificates had been issued from the CA, and providing context about the CA renewal and QuoVadis’s checklist/process changes. QuoVadis accepted the issuance as a mistake and stated that its renew checklists were changed, with follow-up planned to replace the CA with an EKU-constrained version. Jeremy Rowley and Stephen Davidson discussed the interpretation of the requirements and noted process integration steps after the renewal. The CA certificate was revoked/superseded effective October 15, 2019, and a later comment stated that remediation appeared complete. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:01 UTC Revised: 2026-06-16 18:45 UTC Confidence: 0.86 8 comments
Chronology
  1. QuoVadis issued the intermediate “QuoVadis EU Issuing Certification Authority G4” that lacked an extendedKeyUsage extension.
  2. Mozilla policy compliance spot-check identified the non-conforming intermediate and opened the incident bug.
  3. The CA certificate was revoked/superseded via CRL effective October 15, 2019.
  4. A participant indicated remediation was complete.
Thread Activity
  1. Community commenter — Reported that the QuoVadis intermediate issued on 2019-05-14 lacked extendedKeyUsage and included an organizationIdentifier, and requested an Incident Report.
  2. DigiCert — Provided an incident report describing discovery during investigation of bug 1581597, stated no TLS certificates were issued, and outlined corrective actions including changing renew checklists and replacing the CA with an EKU-constrained version.
  3. Community commenter — Questioned QuoVadis’s explanation about misunderstanding applicability to renewals and asked how future confusion would be prevented.
  4. DigiCert — Responded that the QuoVadis PKI team integrated into DigiCert PKI Operations and adopted practices like checklists and review signoffs, and discussed interpretation of BR section 7.1.4.3.1.
  5. Community commenter — Asked for links supporting the asserted confusion and criticized the response as not providing long-term assurances or solutions for future incidents.
  6. DigiCert — Agreed revocation was needed, described integration steps and controls, and said he would coordinate to revoke the ICA right away.
  7. DigiCert — Announced the CA certificate was revoked/superseded effective October 15, 2019 and provided a crt.sh link.
  8. Fastly representative — Stated it appeared all questions were answered and remediation was complete.
Participants
Community commenter DigiCert Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1667518 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-09-26 · Closed 2023-02-22 · 97% similar
QuoVadis: Incorrect keyUsage for ECC certificate
#1589047 RESOLVED Certificate Misissuance Opened 2019-10-16 · Closed 2023-02-22 · 94% similar
QuoVadis: Incorrect EV jurisdiction of incorporation information
#1456655 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-04-24 · Closed 2023-02-22 · 94% similar
DigiCert / ABB: Issues with DN, country code and keyUsage
#1524876 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-02-03 · Closed 2023-02-22 · 87% similar
Entrust: IP in dnsName
#1574594 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-08-16 · Closed 2023-02-22 · 87% similar
Amazon Trust Services: Revoked Sample Certs - No SANs
#1502957 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-10-29 · Closed 2023-02-22 · 86% similar
Camerfirma: MULTICERT Misissuance and missing audits
#1390988 RESOLVED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2017-08-16 · Closed 2023-02-22 · 86% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1600301 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-11-29 · Closed 2023-02-22 · 86% similar
Asseco DS / Certum: EV Certificates issued with wrong Business Category

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action