← DarkMatter LLC cases
Bugzilla #1599916
Certificate Problem Report
QuoVadis: Unconstrained CAs revocation
RESOLVED
FIXED
DarkMatter LLC
AI Summary
QuoVadis identified issues with 18 unconstrained subCAs that were not properly disclosed in their WebTrust for BR report. Following a notification from Ryan Sleevi, QuoVadis committed to revoke these subCAs, with seven already revoked and the remaining two scheduled for revocation. The revocation process faced delays due to COVID-19 restrictions, but all subCAs were ultimately revoked by June 2020. QuoVadis has since implemented measures to prevent similar issues in the future, including the use of explicit EKU in new subCAs.
Chronology
- Ryan Sleevi noted expectations for revocation of unconstrained subCAs.
- Scheduled revocation of the last two subCAs.
- Final two subCAs were revoked.
Participants
Stephen Davidson
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
QuoVadis: N/A in EV serialNumber field
QuoVadis: BR Error - san dns name starts with period
QuoVadis / Freistaat Bayern: Non-BR-compliant Key Usage
QuoVadis: use of Organisationidentifier field in EV (Pre CABF Ballot SC17)
QuoVadis: Incorrect EV businessCategory
QuoVadis / Siemens: Insufficient serial number entropy
QuoVadis: LLB insufficient Serial Number Entropy
QuoVadis: OCSP handling of Certificate Transparency Pre-certs