← DigiCert cases
Bugzilla #1838334 Self Reported Incident

DigiCert: Sub CAs with EV OIDs without EV audit report

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On June 1, 2023, DigiCert issued eight TLS issuing subCAs (ICAs) for external hosting by Microsoft, signed by DigiCert Global Root G2 and DigiCert Global Root G3. During review, DigiCert determined that Microsoft did not have a valid EV audit, but the ICAs contained certificatePolicies including CAB/F EV policy OIDs, making them technically capable of issuing EV certificates without an EV audit. DigiCert revoked the eight mis-issued ICAs on June 6, 2023, and stated that no end-entity certificates were issued from these ICAs at the time of revocation. DigiCert also revised its ICA template for externally operated ICAs to exclude the EV OID and updated its on-prem CA template to make the EV OID optional, generating a test certificate using the corrected profile. In the thread, DigiCert asked whether the case could be closed after remediation was complete, and Mozilla indicated it intended to close the bug on June 23, 2023 unless there were questions. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 11:42 UTC Revised: 2026-06-16 19:12 UTC Confidence: 0.90 4 comments
Chronology
  1. DigiCert issued eight TLS issuing subCAs (ICAs) for external hosting by Microsoft.
  2. The eight mis-issued ICAs were revoked by DigiCert.
  3. DigiCert revised the externally operated ICA template to exclude the EV OID and generated a test certificate.
Thread Activity
  1. Community commenter — DigiCert described how it discovered the issue (EV policy OIDs present without a valid EV audit), provided a timeline, stated the ICAs were revoked, and listed the affected/replacement ICA certificate references.
  2. Community commenter — DigiCert corrected the certificate references in the affected-certificate section, clarifying which were revoked and which were replacements.
  3. Community commenter — DigiCert asked whether the case could be closed since remediation was complete and there were no remaining questions.
  4. Mozilla representative — Mozilla stated it intended to close the bug on Friday, June 23, 2023 unless there were any questions or concerns.
Participants
Community commenter Mozilla representative
Similar Local Cases
#1710444 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-05-10 · Closed 2023-02-22 · 91% similar
DigiCert: Invalid stateOrProvinceName
#1649951 RESOLVED Self Reported Incident Revocation Issue Opened 2020-07-02 · Closed 2023-02-22 · 90% similar
DigiCert: Incorrect OCSP Delegated Responder Certificate
#1845634 RESOLVED Self Reported Incident Opened 2023-07-26 · Closed 2023-09-02 · 90% similar
DigiCert: TLS certificates with incorrect policy OID
#1650910 RESOLVED Self Reported Incident Audit Finding Revocation Issue Opened 2020-07-06 · Closed 2023-02-22 · 89% similar
DigiCert: Inconsistent EV audits
#1894560 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-05-01 · Closed 2024-07-03 · 89% similar
DigiCert: Incorrect case in Business Category
#1647084 RESOLVED Self Reported Incident Incident Opened 2020-06-20 · Closed 2023-02-22 · 87% similar
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
#1714439 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-03 · Closed 2023-02-22 · 87% similar
DigiCert: Incorrect RegNumber-Org Type combination
#1978163 RESOLVED Self Reported Incident Opened 2025-07-18 · Closed 2025-10-29 · 87% similar
DigiCert: Re-use of WHOIS validation shortly after deadline

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action