QuoVadis: Failure to revoke within 7 days: OCSP EKU issue
This case concerns QuoVadis's failure to revoke certain certificates within the required 7-day timeframe due to an issue related to the OCSP EKU. The CA acknowledged that it could not revoke all impacted CAs in the mandated period and provided updates on the complexity of the situation, which involved approximately 1.3 million end entity certificates across 30 issuing CAs. QuoVadis has since ceased using the id-kp-OCSPSigning EKU in new issuing CAs and is reviewing its practices to ensure compliance with the Baseline Requirements. The issue has been resolved with all affected certificates revoked and key destruction completed.
- The remaining Siemens operated subCAs affected by this bug have been revoked.
- DigiCert — QuoVadis acknowledges it will not be able to revoke all impacted CAs in the mandated period.
- DigiCert — QuoVadis explains the complexity of the bug and outlines steps taken to address the issue.
- DigiCert — Final QuoVadis operated CAs have been revoked with key destruction.
- Mozilla representative — The bug is suggested for closure as all necessary actions have been completed.