DigiCert EVG profile compliance CPR for a subordinate CA certificate
This case concerns a Certificate Problem Report about the DigiCert QuoVadis G3 Qualified TLS RSA4096 SHA256 2023 CA1 subordinate CA certificate. DigiCert said the CPR alleged that because the SubCA contained an organizationIdentifier, it also needed a cabfOrganizationIdentifier under the EV Guidelines. DigiCert responded that the CA/B Forum had already clarified that this requirement applies only to Subscriber Certificates and not to SubCAs, and therefore the certificate was not misissued. DigiCert asked for the bug to be closed as INVALID and said it was preparing a full incident report. CCADB later said the bug was proposed to be closed as INVALID on or about 2026-08-03, and the bug is now RESOLVED with resolution INVALID.
- A third party reported an alleged EVG profile non-compliance involving a DigiCert ICA certificate.
- DigiCert received a CPR alleging EVG non-compliance for the QuoVadis G3 Qualified TLS RSA4096 SHA256 2023 CA1 SubCA.
- DigiCert — DigiCert filed a preliminary incident report saying a third party reported a DigiCert ICA profile as non-compliant with an EVG interpretation and asked for a next update on 2026-08-02.
- DigiCert — DigiCert said the CPR’s interpretation was incorrect, cited a CABF clarification that the requirement applies only to Subscriber Certificates, and requested that the bug be closed as INVALID.
- CCADB representative — CCADB said the bug was proposed to be closed as INVALID on or about 2026-08-03 and invited any additional comments before closure.