← DigiCert cases
Bugzilla #2056663 Ca Certificate Compliance Externally Reported Incident Problem Reporting Failure Certificate Misissuance Closure Request

DigiCert EVG profile compliance CPR for a subordinate CA certificate

RESOLVED INVALID DigiCert
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns a Certificate Problem Report about the DigiCert QuoVadis G3 Qualified TLS RSA4096 SHA256 2023 CA1 subordinate CA certificate. DigiCert said the CPR alleged that because the SubCA contained an organizationIdentifier, it also needed a cabfOrganizationIdentifier under the EV Guidelines. DigiCert responded that the CA/B Forum had already clarified that this requirement applies only to Subscriber Certificates and not to SubCAs, and therefore the certificate was not misissued. DigiCert asked for the bug to be closed as INVALID and said it was preparing a full incident report. CCADB later said the bug was proposed to be closed as INVALID on or about 2026-08-03, and the bug is now RESOLVED with resolution INVALID.

Model: gpt-5.4-mini Generated: 2026-07-26 06:23 UTC Revised: 2026-08-16 07:00 UTC Confidence: 0.97 4 comments
Chronology
  1. A third party reported an alleged EVG profile non-compliance involving a DigiCert ICA certificate.
  2. DigiCert received a CPR alleging EVG non-compliance for the QuoVadis G3 Qualified TLS RSA4096 SHA256 2023 CA1 SubCA.
Thread Activity
  1. DigiCert — DigiCert filed a preliminary incident report saying a third party reported a DigiCert ICA profile as non-compliant with an EVG interpretation and asked for a next update on 2026-08-02.
  2. DigiCert — DigiCert said the CPR’s interpretation was incorrect, cited a CABF clarification that the requirement applies only to Subscriber Certificates, and requested that the bug be closed as INVALID.
  3. CCADB representative — CCADB said the bug was proposed to be closed as INVALID on or about 2026-08-03 and invited any additional comments before closure.
Participants
DigiCert CCADB representative
External References
Similar Local Cases
#2032485 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-04 · 96% similar
DigiCert: Misissuance detected by PKIMetal
#2015186 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2026-02-06 · Closed 2026-03-23 · 94% similar
DigiCert: Subject Serial Numbers for Non-Commercial Entities
#2062100 ASSIGNED Ca Certificate Compliance Incident Externally Reported Incident Certificate Misissuance Opened 2026-08-10 Still Open · 87% similar
DigiCert: jurisdictionCountry in EV certificate
#2007219 RESOLVED Ca Certificate Compliance Opened 2025-12-20 · Closed 2026-02-17 · 85% similar
DigiCert: Some certificates issued with CRLDPs that don’t exactly match CCADB disclosures
#2056882 RESOLVED Externally Reported Incident Certificate Misissuance Opened By Ca Single Ca Owner Opened 2026-07-22 · Closed 2026-08-17 · 81% similar
D-Trust: EV Subordinate CA missing required cabfOrganizationIdentifier extension
#1759122 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2022-03-11 · Closed 2022-11-14 · 79% similar
DigiCert: EV for Onion addresses without Tor Service Descriptor
#2053131 RESOLVED Ca Certificate Compliance Externally Reported Incident Problem Reporting Failure Repository Issue Opened 2026-07-07 · Closed 2026-08-18 · 78% similar
TunTrust: OCSP responder "Unknown" of one Pre-certificate
#1675923 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-11-07 · Closed 2024-05-09 · 78% similar
DigiCert: TERENA: Insufficient validation of organizationalUnitName

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action