← DigiCert cases
Bugzilla #1759122 Ca Certificate Compliance Certificate Misissuance

DigiCert: EV for Onion addresses without Tor Service Descriptor

RESOLVED INVALID DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The bug was opened by Michel Le Bihan after he noticed two EV certificates for v3 Onion addresses that did not contain a Tor Service Descriptor hash. He stated that, in his understanding, EV certificates for v3 Onion addresses must include the Tor Service Descriptor hash and referenced CAB Forum discussions about the ambiguity. DigiCert responded that EVG Appendix F allows issuance of EV certificates with “onion” as the right-most domain label for Tor v3 Onion domain names, provided the issuance complies with the requirements in the relevant Baseline Requirements appendices. DigiCert further stated that the requirements in BR Appendix B were fulfilled for these certificates and that BR Appendix B does not require inclusion of the TorServiceDescriptorHash extension. DigiCert also argued that including the TorServiceDescriptorHash provides no security value for Tor v3 onion certificates due to cryptographic improvements in the Tor v3 specification. The bug was resolved with resolution set to INVALID.

Model: gpt-5.4-nano Generated: 2026-06-13 11:40 UTC Revised: 2026-06-16 19:07 UTC Confidence: 0.86 2 comments
Chronology
  1. Michel Le Bihan reported two EV certificates for v3 Onion addresses that lacked the Tor Service Descriptor hash.
  2. DigiCert provided a standards-based response asserting the certificates were issued in compliance and that the extension was not required.
Thread Activity
  1. Lebihan representative — Reported two EV certificates for v3 Onion addresses without a Tor Service Descriptor hash and cited CAB Forum ambiguity, asserting EV should include it.
  2. DigiCert — Responded that EVG Appendix F permits such issuance under the applicable Baseline Requirements and stated there is no BR Appendix B requirement for TorServiceDescriptorHash; also argued it adds no security value for Tor v3.
Participants
Lebihan representative DigiCert Mozilla representative
Similar Local Cases
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 100% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName
#1710856 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-05-12 · Closed 2023-02-22 · 100% similar
DigiCert: Invalid localityName
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 88% similar
DigiCert: Misissuance detected by PKIMetal
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 87% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities
#1586604 RESOLVED Certificate Misissuance Validation Issue Opened 2019-10-06 · Closed 2022-11-14 · 86% similar
DigiCert: TERENA: No localityName in EV precert
#1937693 RESOLVED Certificate Misissuance Opened 2024-12-17 · 86% similar
DigiCert now China CCP Dog,PEM uploaded
#1705647 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-04-16 · Closed 2023-02-22 · 85% similar
KIR S.A.: Invalid organizationName
#1262610 RESOLVED Ca Certificate Compliance Opened 2016-04-06 · Closed 2023-02-22 · 80% similar
DigiCert: ECCE 001 issuing certificates without subject alternative name extension

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action