DigiCert: Sub CAs with EV OIDs without EV audit report
On June 1, 2023, DigiCert issued eight TLS issuing subCAs (ICAs) for external hosting by Microsoft, signed by DigiCert Global Root G2 and DigiCert Global Root G3. During review, DigiCert determined that Microsoft did not have a valid EV audit, but the ICAs contained certificatePolicies including CAB/F EV policy OIDs, making them technically capable of issuing EV certificates without an EV audit. DigiCert revoked the eight mis-issued ICAs on June 6, 2023, and stated that no end-entity certificates were issued from these ICAs at the time of revocation. DigiCert also revised its ICA template for externally operated ICAs to exclude the EV OID and updated its on-prem CA template to make the EV OID optional, generating a test certificate using the corrected profile. In the thread, DigiCert asked whether the case could be closed after remediation was complete, and Mozilla indicated it intended to close the bug on June 23, 2023 unless there were questions. The bug is marked RESOLVED with resolution FIXED.
- DigiCert issued eight TLS issuing subCAs (ICAs) for external hosting by Microsoft.
- The eight mis-issued ICAs were revoked by DigiCert.
- DigiCert revised the externally operated ICA template to exclude the EV OID and generated a test certificate.
- Community commenter — DigiCert described how it discovered the issue (EV policy OIDs present without a valid EV audit), provided a timeline, stated the ICAs were revoked, and listed the affected/replacement ICA certificate references.
- Community commenter — DigiCert corrected the certificate references in the affected-certificate section, clarifying which were revoked and which were replacements.
- Community commenter — DigiCert asked whether the case could be closed since remediation was complete and there were no remaining questions.
- Mozilla representative — Mozilla stated it intended to close the bug on Friday, June 23, 2023 unless there were any questions or concerns.