← DigiCert cases
Bugzilla #1865235 Ca Certificate Compliance

DigiCert: Late background refreshment check

RESOLVED FIXED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

DigiCert reported that its CPS states it performs background checks for trusted role staff at least every 5 years, but during a recent Webtrust review it was noted that 3 of 6 sampled checks were completed between the 5- and 6-year mark. DigiCert stated that the BR’s and root programs do not require this additional background refresh frequency for its public PKI systems, and therefore it reported no impact on public PKI. DigiCert attributed the issue to its CPS not being updated to reflect that the 5-year requirement was no longer applicable, while its people team performed background refreshment every six months for individuals reaching their 5-year anniversary. DigiCert said that depending on when the six-month check ran, the background check could be slightly over the 5-year period, and in this instance the 3 certificates were late by between 2 and 8 months. As a remediation action, DigiCert stated it is removing the background check refresh requirement from its CPS. The bug was marked RESOLVED with resolution FIXED, and DigiCert indicated it was monitoring for community questions before Mozilla closed it.

Model: gpt-5.4-nano Generated: 2026-06-13 11:43 UTC Revised: 2026-06-16 19:13 UTC Confidence: 0.90 4 comments
Chronology
  1. DigiCert’s auditors provided draft Webtrust reports noting 3 of 6 sampled background checks completed between 5 and 6 years.
  2. DigiCert discussed the findings with auditors and agreed it did not track background checks consistently within the 5-year mark.
Thread Activity
  1. Community commenter — Opened the bug describing that DigiCert’s CPS 5-year background refresh requirement was not consistently met (3 of 6 sampled were completed 2–8 months late) and stated it would remove the requirement from the CPS.
  2. Community commenter — Noted DigiCert was monitoring the ticket for any community questions.
  3. Community commenter — Asked if Mozilla was okay to close the ticket.
  4. Mozilla representative — Said they would close the bug on Friday, 1-Dec-2023 unless there were further questions.
Participants
Community commenter Mozilla representative
External References
Similar Local Cases
#1881364 RESOLVED Ca Certificate Compliance Opened 2024-02-21 · Closed 2024-03-29 · 96% similar
Digicert: SMIME certificate with unvalidated information
#1875205 RESOLVED Ca Certificate Compliance Opened 2024-01-18 · Closed 2024-01-26 · 95% similar
Digicert: SMIME certs missing State in Org ID
#1710444 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-05-10 · Closed 2023-02-22 · 88% similar
DigiCert: Invalid stateOrProvinceName
#1714439 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2021-06-03 · Closed 2023-02-22 · 87% similar
DigiCert: Incorrect RegNumber-Org Type combination
#1794050 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2022-10-06 · Closed 2023-02-22 · 87% similar
DigiCert: Org information issue in new validation workflow
#1927506 RESOLVED Ca Certificate Compliance Opened 2024-10-28 · Closed 2025-01-24 · 87% similar
DigiCert: Incorrect OrgID in S/MIME certificates for one customer
#1937210 RESOLVED Ca Certificate Compliance Opened 2024-12-13 · Closed 2025-02-28 · 86% similar
DigiCert: Late incident report for bug 1925106
#1624527 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-03-24 · Closed 2023-02-22 · 85% similar
DigiCert: Issuance of Cert with Compromised Key

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action