← DigiCert cases
Bugzilla #1647084 · Certificate Problem Report
DigiCert / Microsoft: inconsistent disclosure of externally-operated intermediate
DigiCert · RESOLVED
AI Summary
This case addresses a disclosure inconsistency involving DigiCert and Microsoft regarding an intermediate certificate. DigiCert initially reported the intermediate as operated under its own policies, but it was later revealed to be operated by Microsoft. The issue was acknowledged by DigiCert, which initiated an investigation and committed to improving its processes to prevent similar errors in the future.
Chronology
- Bug reported regarding disclosure inconsistency.
- DigiCert acknowledged the error and began investigation.
- DigiCert completed review and identified additional affected CAs.
- DigiCert confirmed full use of new naming document for SubCAs.
- Concerns raised about the quality of incident reports.
Participants
Andrew Ayer
Jeremy Rowley
Brenda Bernal
Ryan Sleevi
B Wilson
External References
Similar Local Cases
DigiCert: Failure to disclose Unconstrained Intermediate within 7 Days
DigiCert: SHA-256 hash algorithm used with ECC P-384 key
DigiCert: Failure to revoke key-compromised certificate
DigiCert: Failure to revoke key-compromised certificates within 24 hours
DigiCert: CAA Checking Issue
DigiCert: Incorrect RegNumber-Org Type combination
DigiCert: Underscores - Citi
DigiCert: Underscores - Ericsson