← DigiCert cases
Bugzilla #2056663 Ca Certificate Compliance Externally Reported Incident Problem Reporting Failure Opened By Ca

DigiCert EVG profile compliance dispute for a subordinate CA certificate

ASSIGNED DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case was opened by DigiCert after a third party reported that a DigiCert ICA profile was allegedly non-compliant with an interpretation of the EV Guidelines. DigiCert later said it received a Certificate Problem Report about the “DigiCert QuoVadis G3 Qualified TLS RSA4096 SHA256 2023 CA1” subordinate CA certificate and described the CPR’s claim that the certificate needed a cabfOrganizationIdentifier because it contained an organizationIdentifier. DigiCert stated that the CA/B Forum had already addressed the interpretation and that the relevant EVG section applies only to Subscriber Certificates, not SubCAs. DigiCert said the certificate was not misissued and asked for the bug to be closed as INVALID. DigiCert also said it was preparing a full incident report and requested a next update date of 2026-08-02.

Model: gpt-5.4-mini Generated: 2026-07-26 06:23 UTC Confidence: 0.93 3 comments
Chronology
  1. A third party reported an alleged EVG profile non-compliance involving a DigiCert ICA certificate.
  2. DigiCert received a CPR alleging EVG non-compliance for the QuoVadis G3 Qualified TLS RSA4096 SHA256 2023 CA1 SubCA.
Thread Activity
  1. DigiCert — DigiCert filed a preliminary incident report saying a third party reported a DigiCert ICA profile as non-compliant with an EVG interpretation and asked for a next update on 2026-08-02.
  2. DigiCert — DigiCert said the CPR’s interpretation was incorrect, cited a CABF clarification that the requirement applies only to Subscriber Certificates, and requested that the bug be closed as INVALID.
Participants
DigiCert
External References
Similar Local Cases
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 79% similar
DigiCert: Misissuance detected by PKIMetal
#2007219 RESOLVED Ca Certificate Compliance Opened 2025-12-20 · Closed 2026-02-17 · 77% similar
DigiCert: Some certificates issued with CRLDPs that don’t exactly match CCADB disclosures
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 76% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities
#2057448 UNCONFIRMED Ca Certificate Compliance Incident Certificate Misissuance Externally Reported Incident Opened 2026-07-24 Still Open · 71% similar
SwissSign: Invalid Entry in State field
#1664325 RESOLVED Ca Certificate Compliance Opened 2020-09-10 · Closed 2023-02-22 · 70% similar
DigiCert: SHA-256 hash algorithm used with ECC P-384 key
#2056223 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Policy Document Issue Opened 2026-07-20 Still Open · 69% similar
D-Trust OCSP Responder Certificates Include CA/B Forum DV Policy OID
#2053131 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Problem Reporting Failure Opened 2026-07-07 Still Open · 69% similar
TunTrust: OCSP responder "Unknown" of one Pre-certificate
#2047843 RESOLVED Ca Certificate Compliance Problem Reporting Failure Revocation Issue Opened 2026-06-16 · Closed 2026-07-09 · 69% similar
Certigna: Pre-certificates not recognised by the OCSP responder

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action