DigiCert EVG profile compliance dispute for a subordinate CA certificate
This case was opened by DigiCert after a third party reported that a DigiCert ICA profile was allegedly non-compliant with an interpretation of the EV Guidelines. DigiCert later said it received a Certificate Problem Report about the “DigiCert QuoVadis G3 Qualified TLS RSA4096 SHA256 2023 CA1” subordinate CA certificate and described the CPR’s claim that the certificate needed a cabfOrganizationIdentifier because it contained an organizationIdentifier. DigiCert stated that the CA/B Forum had already addressed the interpretation and that the relevant EVG section applies only to Subscriber Certificates, not SubCAs. DigiCert said the certificate was not misissued and asked for the bug to be closed as INVALID. DigiCert also said it was preparing a full incident report and requested a next update date of 2026-08-02.
- A third party reported an alleged EVG profile non-compliance involving a DigiCert ICA certificate.
- DigiCert received a CPR alleging EVG non-compliance for the QuoVadis G3 Qualified TLS RSA4096 SHA256 2023 CA1 SubCA.
- DigiCert — DigiCert filed a preliminary incident report saying a third party reported a DigiCert ICA profile as non-compliant with an EVG interpretation and asked for a next update on 2026-08-02.
- DigiCert — DigiCert said the CPR’s interpretation was incorrect, cited a CABF clarification that the requirement applies only to Subscriber Certificates, and requested that the bug be closed as INVALID.