DigiCert incident report on inconsistent EV audit coverage for EV-capable intermediates
DigiCert opened this bug to disclose that some issuing CAs capable of issuing EV certificates had been omitted from EV audit reports. The issue was first identified after a link posted in Mozilla bug 1647084 pointed to a crt.sh disclosure page about inconsistent audits, and DigiCert then confirmed the problem and investigated it internally. DigiCert said it blocked EV issuance for the affected ICAs, planned to replace the ICAs used for EV issuance, and would revoke the impacted EV end-entity certificates. The thread also records DigiCert’s follow-up work on remediation, including revocation updates, an automated audit-reporting tool, and a commitment to include all technically capable EV CAs in future EV audits. Mozilla participants later said the bug could be closed, while also noting that Mozilla would clarify the policy language to require EV-capable CAs to be included in EV audits.
- DigiCert issued the first issuing certificate in scope.
- DigiCert signed the last issuing certificate in scope.
- A crt.sh disclosure about inconsistent audits was posted to Mozilla bug 1647084 and DigiCert began internal investigation.
- DigiCert blocked EV issuance for the affected ICAs and filed this incident report.
- DigiCert posted revoked certificate hashes and additional revocation-related files.
- DigiCert uploaded a sample automated audit report.
- DigiCert said its current EV audit would include all technically capable EV CAs.
- Mozilla said it intended to close the bug and would clarify the policy requirement for EV-capable CAs.
- DigiCert — DigiCert reported that it found EV audit scope issues, blocked EV issuance for affected ICAs, and planned revocation and replacement steps.
- Community commenter — Ryan praised the incident report and asked for clearer timing on the transition plan.
- DigiCert — DigiCert said affected ICAs were being turned off that day, revocation would begin and hopefully finish by July 11, and a separate delayed-revocation report would be filed if needed.
- DigiCert — DigiCert said it had posted a delayed revocation report in bug 1651828 and corrected the revocation deadline timing.
- Mozilla representative — Mozilla said the situation required a well-explained delayed revocation plan and referenced Mozilla’s revocation guidance.
- DigiCert — DigiCert attached revoked hashes and a separate file for certificates affected by COVID, a critical infrastructure case, and a court order.
- DigiCert — DigiCert described manual compliance and PKI operations as the root cause and said it was working to automate audit reporting and other processes.
- DigiCert — DigiCert said the automated audit report was in development and described the report contents and planned delivery through Rootica.
- DigiCert — DigiCert said the automated audit report was working and uploaded a sample report.
- Mozilla representative — Mozilla said it believed the bug could be closed and that Issue 147 would clarify the policy language.
- DigiCert — DigiCert said its current WebTrust for EV audit would include all technically capable EV CAs and that the audit year end had been moved earlier.
- Mozilla representative — Mozilla said it intended to close the bug and that DigiCert’s latest response supported closure.