← DigiCert cases
Bugzilla #1650910 Self Reported Incident Audit Finding Revocation Issue

DigiCert incident report on inconsistent EV audit coverage for EV-capable intermediates

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert opened this bug to disclose that some issuing CAs capable of issuing EV certificates had been omitted from EV audit reports. The issue was first identified after a link posted in Mozilla bug 1647084 pointed to a crt.sh disclosure page about inconsistent audits, and DigiCert then confirmed the problem and investigated it internally. DigiCert said it blocked EV issuance for the affected ICAs, planned to replace the ICAs used for EV issuance, and would revoke the impacted EV end-entity certificates. The thread also records DigiCert’s follow-up work on remediation, including revocation updates, an automated audit-reporting tool, and a commitment to include all technically capable EV CAs in future EV audits. Mozilla participants later said the bug could be closed, while also noting that Mozilla would clarify the policy language to require EV-capable CAs to be included in EV audits.

Model: gpt-5.4-mini Generated: 2026-06-13 11:38 UTC Revised: 2026-06-16 19:04 UTC Confidence: 0.96 36 comments
Chronology
  1. DigiCert issued the first issuing certificate in scope.
  2. DigiCert signed the last issuing certificate in scope.
  3. A crt.sh disclosure about inconsistent audits was posted to Mozilla bug 1647084 and DigiCert began internal investigation.
  4. DigiCert blocked EV issuance for the affected ICAs and filed this incident report.
  5. DigiCert posted revoked certificate hashes and additional revocation-related files.
  6. DigiCert uploaded a sample automated audit report.
  7. DigiCert said its current EV audit would include all technically capable EV CAs.
  8. Mozilla said it intended to close the bug and would clarify the policy requirement for EV-capable CAs.
Thread Activity
  1. DigiCert — DigiCert reported that it found EV audit scope issues, blocked EV issuance for affected ICAs, and planned revocation and replacement steps.
  2. Community commenter — Ryan praised the incident report and asked for clearer timing on the transition plan.
  3. DigiCert — DigiCert said affected ICAs were being turned off that day, revocation would begin and hopefully finish by July 11, and a separate delayed-revocation report would be filed if needed.
  4. DigiCert — DigiCert said it had posted a delayed revocation report in bug 1651828 and corrected the revocation deadline timing.
  5. Mozilla representative — Mozilla said the situation required a well-explained delayed revocation plan and referenced Mozilla’s revocation guidance.
  6. DigiCert — DigiCert attached revoked hashes and a separate file for certificates affected by COVID, a critical infrastructure case, and a court order.
  7. DigiCert — DigiCert described manual compliance and PKI operations as the root cause and said it was working to automate audit reporting and other processes.
  8. DigiCert — DigiCert said the automated audit report was in development and described the report contents and planned delivery through Rootica.
  9. DigiCert — DigiCert said the automated audit report was working and uploaded a sample report.
  10. Mozilla representative — Mozilla said it believed the bug could be closed and that Issue 147 would clarify the policy language.
  11. DigiCert — DigiCert said its current WebTrust for EV audit would include all technically capable EV CAs and that the audit year end had been moved earlier.
  12. Mozilla representative — Mozilla said it intended to close the bug and that DigiCert’s latest response supported closure.
Participants
DigiCert Community commenter Mozilla representative Protonmail representative Fastly representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1515788 RESOLVED Self Reported Incident Opened 2018-12-20 · Closed 2023-02-22 · 100% similar
DigiCert: Underscores - CVS Pharmacy
#1516545 RESOLVED Self Reported Incident Opened 2018-12-27 · Closed 2023-02-22 · 100% similar
DigiCert: Underscores - Verizon
#1548716 RESOLVED Self Reported Incident Opened 2019-05-02 · Closed 2023-02-22 · 100% similar
DigiCert: Verizon: "Default City" in Subject:localityName
#1618256 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-02-26 · Closed 2023-02-22 · 100% similar
DigiCert: Failure to properly encode Subject name
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 100% similar
DigiCert: Issuance of Cert with Compromised Key
#1647084 RESOLVED Self Reported Incident Incident Opened 2020-06-20 · Closed 2023-02-22 · 100% similar
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
#1649277 RESOLVED Self Reported Incident Incident Opened 2020-06-29 · Closed 2023-02-22 · 100% similar
DigiCert: Failure to provide a preliminary report within 24 hours.
#1649951 RESOLVED Self Reported Incident Revocation Issue Opened 2020-07-02 · Closed 2023-02-22 · 100% similar
DigiCert: Incorrect OCSP Delegated Responder Certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action