Digicert: Failure to include CPS URI in 1 certificate
This case describes a Digicert incident involving the issuance of one EV TLS certificate to an affiliate company that had two problems. The certificate failed to include a CPS URI required under the EV Guidelines, and it was a Qualified Website Authentication Certificate (QWAC) whose jurisdiction of incorporation information did not align with organizationID. Digicert reported that the mis-issuance occurred during a demonstration of a new pre-production system designed to support the EU, and that issuance was limited to a single certificate issued through that system during an audit. After receiving notice from Google on 2024-03-25, Digicert investigated and revoked the certificate the same day. Digicert identified a code bug in its EU systems where Qualified certificates were skipping PKIlint because QWACs were not being treated as TLS for linting submission, and it also identified a JOI/organizationID mismatch related to how US state information was handled for EU-qualified profiles. Digicert disabled QWACs on the new platform pending fixes, and later reported that all publicly trusted certificates were being sent through its linter if there are any questions, with Mozilla scheduling closure while noting that linter patching was ongoing.
- Digicert issued an EV TLS certificate that matched the system’s QWAC profile during a demonstration/audit of a new EU pre-production system.
- Digicert revoked the mis-issued certificate after receiving notice from Google and began investigating root cause.
- Digicert disabled QWACs on the new platform pending fixes and discussed completion timing for linter-related work.
- Digicert reported that all publicly trusted certificates were being sent through its linter, and Mozilla scheduled closure.
- Mozilla closed the bug with the understanding that linter patching was ongoing.
- DigiCert — Opened an incident report describing the mis-issued EV TLS/QWAC certificate, including missing CPS URI and JOI/organizationID mismatch, and outlined investigation and planned patches.
- Community commenter — Stated that DigiCert was monitoring the bug for any questions.
- DigiCert — Reported that QWACs were disabled on the new platform pending a fix, and discussed progress and timing for sending remaining certificates through the linter.
- Community commenter — Reported that all publicly trusted certificates are now being sent through the linter and asked whether Mozilla could close the bug.
- Mozilla representative — Indicated closure would be scheduled for the following Wednesday (2024-06-05) unless additional comments or questions.
- Community commenter — Requested ensuring the listed action items were complete, including the three patches and related lints contributed to PKIlint.
- Mozilla representative — Closed the bug with the understanding that linter patching is ongoing, referencing the earlier comments.