DigiCert: EV for Onion addresses without Tor Service Descriptor
The bug was opened by Michel Le Bihan after he noticed two EV certificates for v3 Onion addresses that did not contain a Tor Service Descriptor hash. He stated that, in his understanding, EV certificates for v3 Onion addresses must include the Tor Service Descriptor hash and referenced CAB Forum discussions about the ambiguity. DigiCert responded that EVG Appendix F allows issuance of EV certificates with “onion” as the right-most domain label for Tor v3 Onion domain names, provided the issuance complies with the requirements in the relevant Baseline Requirements appendices. DigiCert further stated that the requirements in BR Appendix B were fulfilled for these certificates and that BR Appendix B does not require inclusion of the TorServiceDescriptorHash extension. DigiCert also argued that including the TorServiceDescriptorHash provides no security value for Tor v3 onion certificates due to cryptographic improvements in the Tor v3 specification. The bug was resolved with resolution set to INVALID.
- Michel Le Bihan reported two EV certificates for v3 Onion addresses that lacked the Tor Service Descriptor hash.
- DigiCert provided a standards-based response asserting the certificates were issued in compliance and that the extension was not required.
- Lebihan representative — Reported two EV certificates for v3 Onion addresses without a Tor Service Descriptor hash and cited CAB Forum ambiguity, asserting EV should include it.
- DigiCert — Responded that EVG Appendix F permits such issuance under the applicable Baseline Requirements and stated there is no BR Appendix B requirement for TorServiceDescriptorHash; also argued it adds no security value for Tor v3.