← DigiCert cases
Bugzilla #1590171 Self Reported Incident

QuoVadis: failure to reply to CPR in a timely manner

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case involves QuoVadis's failure to respond to a Certificate Problem Report (CPR) within the required 24-hour timeframe as stipulated by the CA/Browser Forum Baseline Requirements. The issue was raised by a relying party, Cynthia Revström, who reported potential misissuance of EV certificates. QuoVadis acknowledged the delay and attributed it to a mix-up in their email systems. They have since confirmed the revocation of the misissued certificates and are investigating the broader implications of the miscategorization of 'Non-Commercial Entity' in their EV certificate issuance. The case has been resolved with QuoVadis committing to improve their incident response processes.

Model: gpt-4o-mini Generated: 2026-06-13 20:02 UTC Revised: 2026-06-16 18:47 UTC Confidence: 0.85 23 comments
Chronology
  1. Cynthia Revström submitted a CPR to QuoVadis.
  2. QuoVadis acknowledged the delay in response and began an investigation.
  3. QuoVadis confirmed the revocation of the misissued certificates.
Thread Activity
  1. Cynthia representative — Reported failure to receive a timely response to the CPR.
  2. DigiCert — Acknowledged the delay and stated that the report was received and responded to, but the response was not delivered.
  3. DigiCert — Confirmed the revocation of the misissued certificates and ongoing investigation.
Participants
Community commenter
External References
Similar Local Cases
#1624504 RESOLVED Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 82% similar
QuoVadis: Failure to revoke certificates with compromised private keys
#1579950 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-09 · Closed 2022-11-14 · 79% similar
QuoVadis: OCSP handling of Certificate Transparency Pre-certs
#1738472 RESOLVED Self Reported Incident Opened 2021-10-29 · Closed 2023-02-22 · 79% similar
QuoVadis: hostnames not in preferred name syntax
#1581234 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-09-13 · Closed 2023-02-22 · 78% similar
QuoVadis: EV JOI Issue
#1673119 RESOLVED Self Reported Incident Opened 2020-10-23 · Closed 2023-02-22 · 75% similar
Entrust: Subscriber provides private key with CSR
#1684442 RESOLVED Self Reported Incident Opened 2020-12-29 · Closed 2023-02-22 · 73% similar
DigiCert: SHA-1 intermediate issued after 2016-01-01
#1619359 RESOLVED Self Reported Incident Opened 2020-03-02 · Closed 2023-02-22 · 73% similar
Sectigo: Failure to provide a preliminary report within 24 hours
#1649938 RESOLVED Self Reported Incident Opened 2020-07-02 · Closed 2023-02-22 · 70% similar
QuoVadis: Incorrect OCSP Delegated Responder Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action